M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
Wiz analyzes a supply chain attack in which attackers exploited a misconfigured GitHub Actions workflow to steal a privileged token and publish malicious packages under the @asyncapi npm namespace. The malware executed when the packages were imported, stealing developer credentials and establishing persistence. The report recommends auditing GitHub Actions workflows, applying least privilege to CI/CD tokens, rotating exposed credentials, and strengthening software supply chain security through dependency verification, SBOMs, and continuous monitoring
https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions
Comments
Post a Comment