Supply Chain Attack Targets GitHub Actions via Malicious Ruby Gems and Go Modules
ID: 89c3f271-970f-5104-9885-f469542e803c
STIX ID: report--89c3f271-970f-5104-9885-f469542e803c
Feed Name: Cyber Press
A supply-chain campaign linked to a GitHub account (BufferZoneCorp) distributes malicious Ruby gems (using deceptive names like "knot-...") and Go modules (e.g., github.com/BufferZoneCorp/go-metrics-sdk) that execute during install/initialization to exfiltrate SSH keys, AWS credentials, and GitHub configuration, manipulate CI workflows and dependency resolution (including disabling checksum checks), and establish persistence by appending an SSH public key to authorized_keys; organizations are advised to audit dependencies, rotate exposed credentials, and review CI/CD workflows and environment variables.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
