
We found results for “”
MSC-2025-8499
Good to know:

Date: September 15, 2025
This package version was compromised to include malicious code that steals github secrets, using them to create malicious github actions workflows that help exfiltrate even more github secrets. Besides, the malicious code also uses a data collection endpoint using webhook.site to collect all the stolen data.
Severity Score
Severity Score
Weakness Type (CWE)
Embedded Malicious Code
CWE-506CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |