18.6 C
Lisbon
Tuesday, May 12, 2026
HomeDefencePoisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

A software supply chain attack campaign has been identified using sleeper packages to distribute malicious payloads capable of stealing credentials, tampering with GitHub Actions, and establishing SSH persistence. The activity has been linked to the GitHub account BufferZoneCorp, which published repositories containing malicious Ruby gems and Go modules.

RELATED ARTICLES

Most Popular

Recent Comments