News Score: Score the News, Sort the News, Rewrite the Headlines

@ctrl/tinycolor Supply Chain Attack Post-mortem

TL;DR A malicious GitHub Actions workflow was pushed to a shared repo and exfiltrated a npm token with broad publish rights. The attacker then used that token to publish malicious versions of 20 packages, including @ctrl/tinycolor. My GitHub account, the @ctrl/tinycolor repository were not directly compromised. There was no phishing involved, and no malicious packages were installed on my machine and I already use pnpm to avoid unapproved postinstall scripts. There was no pull request involved b...

Read more at sigh.dev

© News Score  score the news, sort the news, rewrite the headlines