
Cybersecurity
GitHub Actions Attack Steals Credentials
A popular GitHub Actions workflow, `actions-cool/issues-helper`, has been compromised in a supply chain attack. Attackers altered repository tags to point to malicious code designed to steal sensitive credentials from CI/CD environments and send them to an external server.
The Hacker News1 min read