Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
Source: The Hacker News · Category: Supply Chain
Poisoned Ruby gems and Go modules in CI pipelines enable credential theft and SSH persistence. If the firm's development teams use these languages, audit dependencies immediately; compromised build pipelines could exfiltrate client code or secrets.