Cybersecurity

Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories

November 11, 2025 1 min read SkillMX Editorial Desk
Article Data

A malicious package typosquats the legitimate "actionsartifact" package with the intent to target GitHub-owned repositories. "We think the intent was to have this script execute during a build of a GitHub- owned repository, exfiltrate the tokens available to the build environment

Read more on The Hacker News

Loading next article