ended6월 2일· 1 sources

Red Hat Cloud Services 전반에서 악성 npm 패키지 발견

Why it matters

Red Hat Cloud Services' discovery of 95 malicious npm package versions reveals that the CI/CD pipeline itself was compromised via GitHub Actions OIDC, demonstrating supply-chain attack severity beyond simple package vulnerabilities. The incident underscores the necessity of multi-layered defense mechanisms including MFA, staged publishing, and cooldown configurations to prevent recurring supply-chain compromises.

1
Sources
+0
24h
Growth
111d
Active
npmsupply-chain attackRed Hatmalicious packageOIDC

Sources

Related Issues