Disrupting supply chain attacks on npm and GitHub Actions
- In the past year, there’s been a pattern of supply chain attacks that target weaknesses in package repositories and CI/CD systems to quickly spread malware to hundreds of open source projects.
- This malware seeks to exfiltrate credentials both to broadly spread the attack, as well as for later exploitation.
Unverified
- In the past year, there’s been a pattern of supply chain attacks that target weaknesses in package repositories and CI/CD systems to quickly spread malware to hundreds of open source projects.
- This malware seeks to exfiltrate credentials both to broadly spread the attack, as well as for later exploitation.
Sources: Github