研究人员披露 GhostAction 通过恶意 GitHub Actions 工作流窃取凭据
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
AI 导读
研究人员披露,GhostAction 供应链攻击利用受侵的 GitHub 维护者账号,将名为“Security Audit”或“GitHub Actions Security”的恶意工作流植入大量仓库。
推荐理由
披露了通过维护者账号向数万仓库植入恶意 GitHub Actions 工作流的攻击链、泄露凭据范围及处置方法,可帮助团队排查仓库、轮换密钥并降低供应链风险。
来源:The Hacker News · thehackernews.com