PyPI Blog: Token Exfiltration Campaign via GitHub Actions Workflows
(news.ycombinator.com)
1.
2.
PyPI invalidates tokens stolen in GhostAction supply chain attack
(bleepingcomputer.com)
3.
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
(bleepingcomputer.com)