A compromised credential inside a GitHub environment can behave like a master key, and this incident shows how quickly access can become exfiltration and extortion.