ended5월 24일· 1 sources
Mass GitHub Compromise: How Stolen Developer Credentials Enable Supply Chain Attacks
개발자 자격증명 탈취가 촉발한 GitHub 5,000개 저장소 공급망 침해 사건
Why it matters
This campaign reveals a critical threat convergence: infostealers harvesting developer credentials now directly fuel supply chain attacks through GitHub, affecting thousands of repositories at scale. The attackers' exploitation of CI/CD workflows to extract AWS keys, GCP tokens, and SSH credentials transforms personal endpoint vulnerabilities into enterprise-wide infrastructure compromise. Organizations face an urgent security imperative as endpoint threats on developer machines now pose direct supply chain risks to entire cloud environments.
1
Sources
+0
24h
—
Growth
120d
Active
GitHub supply chainCI/CD malwareMegalodoncredential theftinfostealer