URL has been copied successfully!
Fake NPM Package With 206K Downloads Targeted GitHub for Credentials (UPDATED)
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Fake NPM Package With 206K Downloads Targeted GitHub for Credentials (UPDATED)

Veracode Threat Research exposed a targeted typosquatting attack on npm, where the malicious package @acitons/artifact stole GitHub tokens. Learn how this supply chain failure threatened the GitHub organisation’s code.

First seen on hackread.com

Jump to article: hackread.com/fake-npm-package-downloads-github-credentials/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link