Technology ❯ Information Security ❯ Threat Intelligence ❯ Indicators of Compromise
Stolen GitHub credentials let poisoned releases run a Bun‑launched infostealer that harvests developer and cloud secrets, repackages them, and propagates through npm.