Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If they'd waited a week before using their ill-gotten credentials to update the packages, would they have been detected in that week?


That is what the tj-actions attacker did: https://unit42.paloaltonetworks.com/github-actions-supply-ch...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: