TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Large-scale NPM attack targets Azure developers with malicious packages

9 pointsby WalterSobchakabout 3 years ago

1 comment

varunsharma07about 3 years ago
Checkout this GitHub Actions workflow where the outbound calls made by some of these malicious packages are detected. Harden-Runner GitHub Action detects and blocks outbound calls for this exact reason - to identity malicious packages. <a href="https:&#x2F;&#x2F;github.com&#x2F;varunsh-coder&#x2F;supply-chain-goat&#x2F;actions&#x2F;runs&#x2F;2036805074" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;varunsh-coder&#x2F;supply-chain-goat&#x2F;actions&#x2F;r...</a>