Mixed: Supply Chain Attack and California Diaper Contract

Two unrelated stories: attackers injected Miasma malware into AsyncAPI npm packages via compromised GitHub Actions, and California's $6.2 million diaper contract with Baby2Baby came under state audit scrutiny. No connection between these incidents.

2 reportsother · us_mainstream

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Attackers compromised GitHub Actions to inject Miasma malware into legitimate AsyncAPI npm packages, putting development environments at risk. This supply chain attack bypassed standard security measu

mastodon:infosec-exchangeother63d ago kagi ↗

Attackers compromised GitHub Actions to inject Miasma malware into legitimate AsyncAPI npm packages, putting development environments at risk. This supply chain attack bypassed standard security measures by leveraging trusted publishing workflows to distribute malicious code. https:// cybersecuritynews.com/ai-assis ted-linux-kernel-zero-day/