Poisoned Ruby Gems and Go Modules Target CI/CD Pipelines for Credential Theft
A new cybersecurity threat has been discovered where attackers are using fake open-source packages to target developers and automated systems. These attacks involve malicious Ruby gems and Go modules that were uploaded online and made to look like trusted libraries. The main goal of this campaign is to steal sensitive credentials and gain unauthorized access … Continued