HACKREAD

Fake NPM Package With 206K Downloads Targeted GitHub for Credentials_HACKREAD:A0A16B09151687CEBBBD210D40DB4C10

Description

Veracode Threat Research exposed a targeted typosquatting attack on npm, where the malicious package @acitons/artifact stole GitHub tokens. Learn how this supply chain failure threatened the GitHub organisation's code.
Visit Original Source

Basic Information

ID HACKREAD:A0A16B09151687CEBBBD210D40DB4C10
Published Nov 11, 2025 at 11:45

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.