GitHub Workflows (GitHub Actions workflows) are repository-defined automation pipelines that run in CI/CD processes.
GitHub Workflows (GitHub Actions workflows) are repository-defined automation pipelines that run in CI/CD processes. The article notes that Shai-Hulud 2, a new version of the NPM worm, now targets low-code platforms, suggesting potential abuse of automated workflows to propagate or execute malicious payloads within development environments. This widens the attack surface into developer pipelines and supply-chain ecosystems, increasing the significance of protecting workflow configurations and secrets.
The Shai-Hulud malware has re-emerged, infecting over 500 trojanized npm packages and compromising secrets from more than 25,000 developers within three days. The malicious packages, including those from popular…
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…