327 GitHub users were compromised across 817 repositories via malicious GitHub Actions workflows that exfiltrated 3,325 secrets including PyPI, npm, and DockerHub tokens. The stolen tokens were then used to attempt publishing malicious packages downstream.
PACKAGE_ACTIVE_MALWARE on published packages; workflow-level compromise harder to detect
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Partial | PACKAGE_ACTIVE_MALWARE on published packages; workflow-level compromise harder to detect |
| Socket | Missed | GitHub Actions workflow compromise outside package scope |
| Snyk | Missed | No workflow analysis |
| Sonatype (Nexus) | Missed | No workflow analysis |
| Black Duck | Missed | No workflow analysis |
| Endor Labs | Missed | No workflow analysis |