ended6월 2일· 1 sources
Red Hat Cloud Services 전반에서 악성 npm 패키지 발견
Why it matters
Red Hat Cloud Services' discovery of 95 malicious npm package versions reveals that the CI/CD pipeline itself was compromised via GitHub Actions OIDC, demonstrating supply-chain attack severity beyond simple package vulnerabilities. The incident underscores the necessity of multi-layered defense mechanisms including MFA, staged publishing, and cooldown configurations to prevent recurring supply-chain compromises.
1
Sources
+0
24h
—
Growth
111d
Active
npmsupply-chain attackRed Hatmalicious packageOIDC