Supply Chain Compromise via GitHub Actions OIDC Token Extraction and Cache Poisoning
Attackers exploited a pull_request_target misconfiguration combined with GitHub Actions cache poisoning and in-memory OIDC token extraction to publish 84 malicious npm package versions under a trusted publisher identity, delivering credential-harvesting malware at install time.