#GitHubAttack
Checkmarx confirms data theft after a March 23 Trivy supply chain attack hijacked GitHub Action tags and poisoned packages with malware. Source code, employee data, API keys, and credentials were stolen. #SupplyChain #GitHubAttack #Israel
Checkmarx Confirms Data Stolen in Supply Chain Attack
Checkmarx confirmed its KICS open source project was compromised after a March 23 Trivy supply chain attack that let attackers hijack GitHub Action tags and poison packages to reference malware. The intrusion, attributed to TeamPCP and apparently leveraged with Lapsus for monetization, led to the exfiltration of source code, employee databases,...
www.hendryadrian.com
April 29, 2026 at 3:45 PM
Trivy’s GitHub Actions were breached via 75 force-pushed tags, injecting a Python infostealer that exfiltrates CI/CD secrets and developer tokens. Attack linked to hackerbot-claw and TeamPCP. #DevOpsSecurity #GitHubAttack #TeamPCP
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
Trivy, the Aqua Security vulnerability scanner, was compromised again to deliver a Python-based infostealer via malicious releases and force-pushed tags in the aquasecurity/trivy-action and aquasecurity/setup-trivy GitHub Actions, exposing CI/CD secrets and developer credentials. The payload harvests environment variables and tokens, tries to exfiltrate data to scan.aquasecurtiy[.]org or stage it in a...
www.hendryadrian.com
March 21, 2026 at 12:40 AM
StepSecurity uncovered the ForceMemo campaign injecting malware into hundreds of Python repos on GitHub since March 8, 2026. Investigation revealed bulk-registered look-alike domains and IPs tied to a French ISP. #ForceMemo #GitHubAttack #France
ForceMemo in the DNS Spotlight
StepSecurity uncovered the ForceMemo campaign that injected the same malware into hundreds of Python repositories on developers' GitHub accounts beginning 8 March 2026, and traced 20 initial IoCs (nine subdomains, five domains, six IPs) plus dozens to hundreds of related artifacts. The investigation found bulk-registered look-alike domains, domains likely registered with malicious intent, numerous email-connected and string-connected domains, and IPs geolocated to a single French ISP. #ForceMemo #GitHub
www.hendryadrian.com
April 23, 2026 at 10:00 PM
Heads up, developers! GitHub has been hit with a complex cyberattack targeting its supply chain. Stay vigilant and keep your code secure! #CyberSecurity #GitHubAttack #security #privacy #cloud #cyber #infosec #DevCommunity www.darkreading.com/application-...
GitHub Developers Hit in Complex Supply Chain Cyberattack
The attacker employed various techniques, including distributing malicious dependencies via a fake Python infrastructure linked to GitHub projects.
www.darkreading.com
March 25, 2024 at 4:16 PM