4 ms·
How did PYPI_PUBLISH lead to a full GH account takeover?
by redrove 7mo ago
How did PYPI_PUBLISH lead to a full GH account takeover?
- franktankbank 7mo agoDon't hold your breath for an answer.
- ezekg 7mo agoI'd imagine the attacker published a new compromised version of their package, which the author eventually downloaded, which pwned everything else.
- chunky1994 7mo agoTheir Personal Access Token must’ve been pwned too, not sure through what mechanism though
- Imustaskforhelp 7mo agoThey have written about it on github to my question: Trivvy hacked (https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/ https://www.aquasec.com/blog/trivy-supply-chain-attack-what-...) -> all circleci credentials leaked -> included pypi publish token + github pat -> | WE DISCOVER ISSUE | -> pypi token deleted, github pat deleted + account removed from org access, trivvy pinned to last known safe version (v0.69.3) What we're doing now: Block all releases, until we have completed our scans Working with Google's mandiant.security team to understand scope of impact Reviewing / rotating any leaked credentials https://github.com/BerriAI/litellm/issues/24518#issuecomment-4119972374 https://github.com/BerriAI/litellm/issues/24518#issuecomment...
- franktankbank 7mo agoDoes that explain how circleci was publishing commits and closing issues?
- celticninja 7mo ago69.3 isnt safe. The safe thing to do is remove all trivy access. or failing that version. 0.35 is the last and AFAIK only safe version. https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise https://socket.dev/blog/trivy-under-attack-again-github-acti...
- Imustaskforhelp 7mo agoI have sent your message to the developer on github and they have changed the version to 0.35.0 ,so thanks. https://github.com/BerriAI/litellm/issues/24518#issuecomment-4120401246 https://github.com/BerriAI/litellm/issues/24518#issuecomment...