@redhat-cloud-services publish pipeline is compromised today and shipped a signed, trusted, malicious npm package

작성자

카테고리:

← 피드로
r/programming · /u/BattleRemote3157 · 2026-06-01 개발(SW)

[email protected] went out through the project's own github action OIDC trusted publisher today and not any stolen token or a typosquat anything, we saw that the actual release pipeline produced it. this runs on npm install, steals cloud creds and self propagates by injecting fake…

원문 보기 ↗

코멘트

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다