THREAT OPS › Threat News › Disrupting supply chain attacks on npm and GitHub Actions
Disrupting supply chain attacks on npm and GitHub Actions
<p class="wp-block-paragraph">In the past year, there’s been a pattern of supply chain attacks that target weaknesses in package repositories and CI/CD systems to quickly spread malware to hundreds of open source projects. This malware seeks to exfiltrate credentials both to broadly spread the attack, as well as for later exploitation.</p>
<p class="wp-block-paragraph">We’ve written
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- https://docs.npmjs.com/trusted-publishersurl