#cicd-token-abuse

[ follow ]
Information security
fromSecurityWeek
13 hours ago

TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

A coordinated Mini Shai-Hulud supply chain attack compromised 170+ packages, stealing tokens and credentials and spreading via CI publishing of malicious package versions.
[ Load more ]