[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRHbb4nOIjtcQgnRTm235O-FPMPVjFKpv_PXPdCyaMgA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"d83d81b0-3f59-468a-92e3-173838b0ed92","malicious-npm-package-exploits-github-actions-workflow-to-steal-cloud-credentials","87b4b684-5ed4-4bd2-8944-ee6f766cbf77","Malicious npm Package Exploits GitHub Actions Workflow to Steal Cloud Credentials","Attackers compromised the widely-used npm package @7nohe\u002Fopenapi-react-query-codegen by exploiting a poorly scoped GitHub Actions workflow that allowed untrusted fork contributors to trigger package publishing under the legitimate repository's trusted identity. Ten malicious versions were published with valid npm provenance attestations, creating a false sense of legitimacy and bypassing common trust signals. The malicious code executed at install time, targeting high-value secrets including cloud credentials, package registry tokens, and GitHub Actions secrets — and was capable of self-propagation. This attack illustrates how CI\u002FCD pipeline misconfigurations can be weaponized to undermine even signed, attested software supply chains.","**Immediate actions:**\n- Audit all GitHub Actions workflows for `pull_request_target` or comment-triggered events that grant write or publish permissions to untrusted contributors.\n- Rotate any cloud credentials, npm tokens, and GitHub Actions secrets that may have been exposed by installing affected versions of the package.\n- Pin all npm dependencies to exact, verified commit SHAs or checksums rather than mutable version tags.\n\n**Long-term improvements:**\n- Enforce least-privilege scoping on CI\u002FCD publishing workflows so only explicitly trusted, protected branches or maintainer-controlled events can trigger package releases.\n- Implement a software composition analysis (SCA) tool in your pipeline to continuously monitor for newly flagged malicious packages in your dependency tree.\n- Establish an internal package mirroring or vetting process before allowing new third-party npm packages into production builds.\n\n**Detection measures:**\n- Monitor runtime behavior of npm install scripts using tools like Socket.dev, Snyk, or similar supply chain security platforms that flag install-time code execution.\n- Set up alerting for unexpected outbound network connections originating from build or CI\u002FCD environments, which may indicate credential exfiltration.\n- Regularly review npm provenance attestations critically — treat attestation as one signal, not a sole trust indicator, and cross-reference with maintainer activity logs.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-204C: CI\u002FCD Pipeline Security","NIST AC-6: Least Privilege","NIST SA-12: Supply Chain Protection","SLSA Supply Chain Levels for Software Artifacts (Levels 3–4)","OpenSSF Scorecard: Token-Permissions and Branch-Protection checks","SSDF PW.4: Reuse Existing, Well-Secured Software (vetting third-party components)","published","2026-08-29T00:21:04.518087+00:00","2026-08-29T00:21:04.176+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fopenapi-react-query-codegen-npm-compromise?utm_medium=feed","openapi-react-query-codegen-compromised-in-mini-shai-hulud-npm-supply-chain-atta-f17d85","OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[49,55],{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"07ac7272-5223-4c81-a7f9-c4850454eef1","2026-08-30","morning","ThreatNoir Weekend Brief — August 30","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-30\u002Fthreatnoir-morning-brief-2026-08-30.mp3",{"id":56,"date":57,"edition":52,"title":58,"audio_url":59},"dba25329-5397-4372-abf5-4e824e3c58cd","2026-08-29","ThreatNoir Weekend Brief — August 29","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-29\u002Fthreatnoir-morning-brief-2026-08-29.mp3"]