CyberHighReportedAccelerating
7.1
Sophisticated Malicious npm Packages Evade Defenses; Possible Nation-State Origin
Schneier on SecurityLO·3 days ago
Two third-party GitHub Actions, previously compromised in the Mini Shai-Hulud campaign, were re-enabled by their maintainer and remained accessible for over a week while still pointing to malicious code. The re-enabling suggests a lapse in remediation or a deliberate act, and the continued availability of the malicious actions poses a supply-chain risk to downstream users.