Active Flaws in PowerShell Gallery Expose Users to Attacks
ID: fa1ee550-1522-5297-9719-2a97d5fbee37
STIX ID: report--fa1ee550-1522-5297-9719-2a97d5fbee37
Feed Name: Aqua Security Blog
Aqua Nautilus discovered three security flaws in the PowerShell Gallery—permissive package naming that enables typosquatting, spoofable package metadata that masks true ownership, and an API that leaks unlisted package versions (exposing secrets). They built a PoC malicious module (Az.Table) that executed on import and received callbacks from cloud hosts, demonstrating realistic supply-chain and credential-exposure risks; Microsoft was notified but fixes appear incomplete as of August 2023.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
