PyPI Blog: Token Exfiltration Campaign via GitHub Actions Workflows
3 miketheman 1 9/16/2025, 9:09:47 PM blog.pypi.org ↗
Comments (1)
miketheman · 41m ago
Incident report of a recent attack campaign targeting GitHub Actions workflows to exfiltrate PyPI tokens, our response, and steps to protect your projects.