National Cyber Warfare Foundation (NCWF)

Fake NPM Package With 206K Downloads Targeted GitHub for Credentials


0 user ratings
2025-11-11 11:47:03
milo
Blue Team (CND)
Veracode Threat Research exposed a targeted typosquatting attack on npm, where the malicious package @acitons/artifact stole GitHub tokens. Learn how this supply chain failure threatened the GitHub organisation's code.

Deeba Ahmed

Source: HackRead
Source Link: https://hackread.com/fake-npm-package-downloads-github-credentials/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.