#github-command-and-control

[ follow ]
Information security
fromtheregister
6 hours ago

Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

An npm account compromise injected malware into 314 packages, stole cloud and GitHub credentials, and used GitHub as command-and-control via automated token-driven activity.
[ Load more ]