security1 distinct publisher
Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build
Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.
Publishers:unit42.paloaltonetworks.com
Reality
- Evidence55
- Adoption62
- Hype gap+18
- Incentives80
- Confidence52