Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

Source: The Hacker News  ·  Category: Supply Chain


Poisoned Ruby gems and Go modules in CI pipelines enable credential theft and SSH persistence. If the firm's development teams use these languages, audit dependencies immediately; compromised build pipelines could exfiltrate client code or secrets.

→ Read the full article

Read more