Anatomy of a Two-Stage Supply-Chain Worm
35 repos in 54 minutesOne trojaned public repository compromised a developer laptop. Sixty-four days later, the stolen GitHub token was used to inject malware into 35 repositories in 54 minutes. Full timeline, both injection vectors, the commit-forgery tells, blockchain-resolved C2, verbatim IOCs — and the four conclusions the investigation got wrong before it got it right.
SecuritySupply ChainIncident ResponseGitHub
Read the post →