THREATOPS
THREAT OPSThreat News › Disrupting supply chain attacks on npm and GitHub Actions

Disrupting supply chain attacks on npm and GitHub Actions

medgithub_security_labPublished 2026-07-28

<p class="wp-block-paragraph">In the past year, there&rsquo;s been a pattern of supply chain attacks that target weaknesses in package repositories and CI/CD systems to quickly spread malware to hundreds of open source projects. This malware seeks to exfiltrate credentials both to broadly spread the attack, as well as for later exploitation.</p>

<p class="wp-block-paragraph">We&rsquo;ve written

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.blog/security/supply-chain-security/disrupting-supply-chain-attacks-on-npm-and-github-actions/