M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
wiz.io | incident | #supply-chain | #malware | #github-actions | #npm | #ci-cd-security | #asyncapi | #pwn-request
Summary
Four @asyncapi npm packages (5 versions) shipped after an attacker exploited a 'pwn request' in an asyncapi/generator GitHub Actions workflow to steal a bot token; the payload runs on import.
- Published
- Collected
Skip to content