Technology ❯ Cybersecurity ❯ Threat Intelligence ❯ Malware Analysis
Researchers say attackers used compromised push access to abuse the project's GitHub Actions release workflow and publish poisoned packages that fetch a large, multi‑channel command framework from IPFS.