Malicious NPM Package Found Targeting GitHub By Typosquatting on GitHub Action Packages | Veracode
Application Security for the AI Era | Veracode
A fake npm package was caught pretending to be GitHub’s real one.
~acitons/artifact (with the typo) tried to steal build tokens from GitHub repos.
It ran a postinstall script that sent secrets to a fake GitHub site.
