Skip to main content

Tag: provenance attestation

1 article

Software development workspace with laptop, notes, and package documentation on a cluttered surface.

Attackers Exploit npm Trusted Publishing in GHAPPIER Supply Chain Campaign

Malicious actors have cleverly exploited npm's trusted publishing feature to unleash a supply-chain attack, using a hijacked maintainer account to distribute a sneaky loader called GHAPPIER. They got away with it by hiding behind a valid provenance attestation, highlighting a loophole in the system.

Analyst 207