Attackers compromised AsyncAPI GitHub repos, exploited CI/CD pipelines with OIDC trusted publishing, and distributed five malicious npm packages with valid SLSA https:// deafnews.it/en/article/asyncap

Attackers compromised AsyncAPI GitHub repos, exploited CI/CD pipelines with OIDC trusted publishing, and distributed five malicious npm packages with valid SLSA https:// deafnews.it/en/article/asyncap i-5-malicious-npm-packages-with-valid-slsa-attestations-distributed-for-hours

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Attackers compromised AsyncAPI GitHub repos, exploited CI/CD pipelines with OIDC trusted publishing, and distributed five malicious npm packages with valid SLSA https:// deafnews.it/en/article/asyncap

mastodon:infosec-exchangeother68d ago kagi ↗

Attackers compromised AsyncAPI GitHub repos, exploited CI/CD pipelines with OIDC trusted publishing, and distributed five malicious npm packages with valid SLSA https:// deafnews.it/en/article/asyncap i-5-malicious-npm-packages-with-valid-slsa-attestations-distributed-for-hours