Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
ID: 71de76df-65eb-5f6c-8a93-aec73ee8bf88
STIX ID: report--71de76df-65eb-5f6c-8a93-aec73ee8bf88
Feed Name: The Hacker News
A supply-chain campaign attributed to the GitHub account BufferZoneCorp distributed malicious Ruby gems and Go modules (including sleeper packages) that harvest environment variables, SSH keys, and credentials, exfiltrate data to a webhook, tamper GitHub Actions workflows via fake Go wrappers, and add a hard-coded SSH public key for persistence; affected packages have been yanked/blocked and users are urged to remove them, rotate exposed credentials, and review for unauthorized changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
