#github-compromise

[ follow ]
Information security
fromIT Pro
3 days ago

Shai-Hulud malware is back with a vengeance and hit more than 19,000 GitHub repositories so far - here's what developers need to know

Shai-Hulud worm infects npm packages, compromising ~700 packages and over 19,000 GitHub repositories to exfiltrate credentials, spread malicious payloads, and delete user files.
fromInfoWorld
2 weeks ago

How GlassWorm wormed its way back into developers' code - and what it says about open source security

Just a little over two weeks after GlassWorm was declared "fully contained and closed" by the open source OpenVSX project, the self-propagating worm is once again targeting Visual Studio Code extensions, add-ons that enhance open source VS Code, providing new features, debuggers, and other tools to improve developer workflows. Researchers from Koi have discovered a new wave of infections and three more compromised extensions.
Information security
#oauth-token-theft
fromIT Pro
2 months ago
Information security

Salesloft Drift hackers had access to company GitHub account for months before attacks

fromIT Pro
2 months ago
Information security

Salesloft Drift hackers had access to company GitHub account for months before attacks

fromTheregister
2 months ago

Drift attackers gained entry via a Salesloft GitHub account

The Salesloft Drift breach that compromised "hundreds" of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft GitHub account in March. This new information comes from a Saturday update into the Mandiant-led investigation - Salesloft hired the incident response firm to determine the root cause and scope of the incident - and a Sunday alert that the integration between Salesloft and Salesforce has now been restored.
Information security
[ Load more ]