Five AsyncAPI npm packages with 2.9 million weekly downloads were trojanized after a GitHub Actions token theft.
Packagist maintainers discovered a GitHub Actions token leak that could allow attackers to compromise PHP package distribution, prompting an urgent…
Sign in to your account
Remember me