← Back to feed
general GBHackers

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

GBHackers Microsoft

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in sof...

T1195
Read the full story GBHackers →

Related Coverage

general NVIDIA Infrastructure Controller Hit by 14 Flaws Enabling Code Execution and Privilege Escalation GBHackers · Sep 23 general ManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen GBHackers · Sep 23 general Critical WordPress Flaw Lets Unauthenticated Attackers Execute Remote Code GBHackers · Sep 23