logo

RoguePuppet software supply chain exposure: Lessons learned

ID: 43c68447-4c3a-5344-a8e9-a14d47b26862

STIX ID: report--43c68447-4c3a-5344-a8e9-a14d47b26862

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2024-07-30

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

A critical supply-chain exposure named RoguePuppet was discovered in Puppet Forge: a GitHub Actions CI/CD misconfiguration allowed any GitHub user to obtain Puppet's API token and push unauthorized backdoored modules. Researcher Adnan Khan disclosed the issue, Puppet revoked the token and patched repositories, and the report highlights the broad potential impact to organizations using Puppet as well as recommended CI/CD and supply-chain security practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.