Tag: provenance attestation
1 article

Attackers Exploit npm Trusted Publishing in GHAPPIER Supply Chain Campaign
Malicious actors have cleverly exploited npm's trusted publishing feature to unleash a supply-chain attack, using a hijacked maintainer account to distribute a sneaky loader called GHAPPIER. They got away with it by hiding behind a valid provenance attestation, highlighting a loophole in the system.