IncidentHow Stolen Credentials Turned GitHub Actions Into a Malware Factory
What Happened TeamPCP compromised the CI/CD pipeline for Trivy, a widely-used vulnerability scanner, by stealing publishing credentials. They used these credentials to push malicious versions of both






