Technology ❯ Cybersecurity ❯ Malware ❯ Supply Chain Attacks
Researchers say attackers used compromised push access to abuse the project's GitHub Actions release workflow and publish poisoned packages that fetch a large, multi‑channel command framework from IPFS.