Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack

Evidence shows a SpotBugs token compromised in December 2024 was used in the March 2025 GitHub Actions supply chain attack.

The post Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack appeared first on SecurityWeek.

Read more: Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack

Story added 4. April 2025, content source with full text you can find at link above.