Cloud · InfosecFeed Brief
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
Cloud
What you need to know
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. In the keyv/cacheable compromise that has been unfolding since yesterday, it is the one thing you should…
Source transparency
Read the original report at SANS Internet Storm Center ↗
This is an InfosecFeed curated brief based on reporting from SANS Internet Storm Center. InfosecFeed does not claim ownership of the original reporting.