Skip to content
Malicious npm Package Targets GitHub Actions Workflows

Malicious npm Package Targets GitHub Actions Workflows

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A typosquatted npm package named '@acitons/artifact' infiltrated GitHub Actions, targeting CI/CD workflows. This malicious package was designed to steal tokens and publish harmful artifacts, affecting developers using GitHub for continuous integration and deployment. The incident highlights the risks associated with package management in software development.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)