security1 publisher
Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks
Google Threat Intelligence Group's September 8 report puts a financially motivated actor, UNC6780, inside PyPI, npm and Docker Hub, publishing under stolen maintainer automation and reselling the AI tool credentials it collects afterwards.
Publishers:infosecurity-magazine.com
Reality
- Evidence54
- Adoption45
- Hype gap+22
- Incentives64
- Confidence56