logo

Supply-Chain Attack via Force Pushes on Plone GitHub Repositories (Campaign)

ID: 913a8d73-6859-551f-9570-57d99dd70a77

STIX ID: report--913a8d73-6859-551f-9570-57d99dd70a77

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2026-01-31

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

In January 2026 the Plone security team disclosed a supply-chain incident where an attacker who had access to a dormant contributor account used force-pushes to overwrite history and insert obfuscated malicious JavaScript into multiple repositories (primarily build-related files targeting developers). Most changes were detected and reverted, but at least one malicious commit reached a protected branch; the incident underscores risks from stale permissions, force-push allowances, and insufficient repository monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.