← Back to feed
general GBHackers

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

GBHackers Microsoft

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in sof...

T1195
Read the full story GBHackers →

Related Coverage

general US sanctions Iranian cyber actors as UK discloses power plant attack The Record · Aug 24 general SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules Cyberscoop · Aug 24 general AWS patches flaw in 7 SDKs SC Media · Aug 24