Diamond Member ThaHaka 0 Posted November 11, 2025 Diamond Member Share Posted November 11, 2025 This is the hidden content, please Sign In or Sign Up Cybersecurity researchers have discovered a malicious npm package named "@acitons/artifact" that typosquats the legitimate "@actions/artifact" package with the intent to target GitHub-owned repositories. "We think the intent was to have this script execute during a build of a GitHub-owned repository, exfiltrate the tokens available to the build environment, and then use those tokens to publish This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/287803-h4ckn3wsresearchers-detect-malicious-npm-package-targeting-github-owned-repositories/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.