ThreatPaper

#provenance

1 case

The malicious release carried valid SLSA provenance and passed every integrity check, because the honest build pipeline compiled source that was already poisoned. It also ran when a developer merely opened the folder.

Supply Chain AttackMalware