M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

Wiz analyzes a supply chain attack in which attackers exploited a misconfigured GitHub Actions workflow to steal a privileged token and publish malicious packages under the @asyncapi npm namespace. The malware executed when the packages were imported, stealing developer credentials and establishing persistence. The report recommends auditing GitHub Actions workflows, applying least privilege to CI/CD tokens, rotating exposed credentials, and strengthening software supply chain security through dependency verification, SBOMs, and continuous monitoring 

https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Open-SPDD proposes an open framework for Spec-Driven Development workflows