๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

StepSecurity
@step_security
Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner
๊ฐ€์ž… November 2021
23 ํŒ”๋กœ์ž‰ ์ค‘    781 ํŒฌ
๐Ÿšจ Breaking: 31 npm packages from @RedHat have been compromised. 100,000+ weekly downloads affected. The upstream CI/CD pipeline was compromised, with all packages published via GitHub Actions OIDC. The payload: โš ๏ธ Reads GitHub Actions runner process memory to extract masked secrets โš ๏ธ Sweeps credentials across AWS, GCP, Azure, K8s, Vault, and npm โš ๏ธ Self-propagating worm that republishes backdoored packages using stolen npm tokens, bypassing 2FA โš ๏ธ Persists on dev machines via Claude Code settings hijack and VS Code task injection โš ๏ธ Exfiltrates data through GitHub API commits, blending in with normal git operations We have responsibly disclosed the incident to the maintainers. Full technical analysis:
๋” ๋ณด๊ธฐ