Red Hat npm Miasma: Trusted CI/CD Publishing Used to Poison 32 Packages
Attackers swiped a GitHub Actions OIDC token from Red Hatβs CI/CD pipeline and used it to publish 32 trojanized npm packages under the @redhat-cloud-services scope, Microsoft Threat Intelligence...