A poisoned version of the mrmustard Python library from Xanadu was published to run an information stealer that harvests SSH keys, AWS credentials, and Kubernetes configurations. The attack exploited the maintainer's GitHub account and CI runners.
A poisoned version of the mrmustard Python library from Xanadu was published to run an information stealer that harvests SSH keys, AWS credentials, and Kubernetes configurations. The attack exploited the maintainer's GitHub account and CI runners.