
Research
/Security News
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
GitHub account BufferZoneCorp published sleeper packages that later added credential theft, GitHub Actions tampering, fake go wrappers, and SSH persistence.





