logoalt Hacker News

redroveyesterday at 4:08 PM3 repliesview on HN

How did PYPI_PUBLISH lead to a full GH account takeover?


Replies

ezekgyesterday at 5:21 PM

I'd imagine the attacker published a new compromised version of their package, which the author eventually downloaded, which pwned everything else.

chunky1994yesterday at 5:24 PM

Their Personal Access Token must’ve been pwned too, not sure through what mechanism though

show 1 reply
franktankbankyesterday at 4:29 PM

Don't hold your breath for an answer.