#self-hosted-runners

[ follow ]
#github-actions
Information security
fromThe Hacker News
1 month ago

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

A renewed Sha1-Hulud supply-chain campaign compromises hundreds of npm packages, executes malicious preinstall scripts, registers self-hosted runners, and exfiltrates secrets.
[ Load more ]