Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordinated compromise of the widely used @asyncapi npm organization, where adversaries leveraged trusted CI/CD pipelines to publish backdoored packages with valid cryptographic provenance. […]
Read the original article: