Researchers Detect Malicious npm Package Targeting GitHub-Owned Repositories
November 11, 2025
1 min read
●
SkillMX Editorial Desk
A malicious package typosquats the legitimate "actionsartifact" package with the intent to target GitHub-owned repositories. "We think the intent was to have this script execute during a build of a GitHub- owned repository, exfiltrate the tokens available to the build environment