CyberMaterial

CyberMaterial

Alerts

Npm Package Targets GitHub Repos

CyberMaterial's avatar
CyberMaterial
Nov 12, 2025
∙ Paid

Cybersecurity researchers have uncovered a malicious npm package named “@acitons/artifact” that employed typosquatting to mimic the legitimate “@actions/artifact” package, specifically aiming at repo…

User's avatar

Continue reading this post for free, courtesy of CyberMaterial.

Or purchase a paid subscription.
© 2026 CyberMaterial · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture