Malicious npm Package Targets GitHub Actions Workflows

Malicious npm Package Targets GitHub Actions Workflows

First seen 2 Dec 2025, 18:33 UTC ThehackernewsInfoworld 7.4

Article Content

Browse articles
ThreatCluster

A typosquatted npm package named '@acitons/artifact' infiltrated GitHub Actions, targeting CI/CD workflows. This malicious package was designed to steal tokens and publish harmful artifacts, affecting developers using GitHub for continuous integration and deployment. The incident highlights the risks associated with package management in software development.