Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»GITHUB steals 3325 mystery in supply chain attack
    Security

    GITHUB steals 3325 mystery in supply chain attack

    PineapplesUpdateBy PineapplesUpdateSeptember 8, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    GITHUB steals 3325 mystery in supply chain attack
    Share
    Facebook Twitter LinkedIn Pinterest Email


    GITHUB steals 3325 mystery in supply chain attack

    Investigators later found similar malicious workflows in at least five public repository and estimated ten private people. The attack was highly adaptive, with container registry credentials to cloud provider keys target environment-specific secrets.

    Researchers said in the blog, “The attack pattern remained in line with all the projects. The attacker first calculated the mystery with legitimate workflow files, then these secret names hardcoded in malicious workflows.” Ghostation used thousands of sensitive tokens, which could be used to tamper with package, access to unauthorized infrastructure, or further supply chain.

    The danger contained within days

    The Gitguardian’s security team quickly responded after finding out, and the fastuced package was set to read by the PyPI administrators within minutes. The malicious committe was returned shortly after. Gitguardian informed the maintenance of the affected repository, successfully approached 573 projects, while Github, NPM, and the PyPI security teams also alerted the misuse of misuse.

    Attack chain Github mystery steals supply
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe new AI AI facility of Amazon Music produces individual playlists every Monday
    Next Article Hackers hijack the NPM package with 2 billion weekly download in the supply chain attack
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How I used GPT-5.2-Codecs to solve a mystery bug and hosting nightmare in less than an hour

    January 19, 2026
    Startups

    Your Bluetooth headphones may be under attack – here’s what to do next

    January 15, 2026
    Startups

    Your smart home is at risk – 6 ways to protect your devices from attack

    December 6, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.