Skip to content
Malicious npm Package Targets GitHub Actions Workflows

Malicious npm Package Targets GitHub Actions Workflows

First seen 12 Nov 2025, 19:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A typosquatted npm package named '@acitons/artifact' infiltrated GitHub Actions, compromising CI/CD workflows by stealing tokens and publishing malicious artifacts. This incident affects developers using GitHub for continuous integration and deployment, highlighting vulnerabilities in package management systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)