← Back to feed
general GBHackers

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

GBHackers • • Microsoft

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in sof...

T1195
Read the full story GBHackers →

Related Coverage

general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10 general Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks BleepingComputer · Oct 9 general Friday Squid Blogging: I Caught a Squid Schneier on Security · Oct 9