Supply-chain threat intelligence
Risk score
92
Indexed incident for github.com/BufferZoneCorp/config-loader (go).
This package is a malicious packages part of the Go BufferZoneCorp and RubyGems knot-theory clusters.
The packages in this cluster steal credentials, set up ssh access and tamper with build/workflow environmetn variables.
Timeline