build1 distinct publisher
A comment-triggered Actions workflow published ten malicious npm versions with valid provenance
Socket says all ten bad tarballs of @7nohe/openapi-react-query-codegen carry genuine GitHub Actions attestations, which is what you get when the attestation covers where a build ran rather than who wrote the commit it built.
Publishers:socket.dev
Reality
- Evidence66
- Adoption58
- Hype gap+10
- Incentives72