Briefing

BufferZoneCorp Uses Sleeper Packages to Deploy Credential Theft and GitHub Actions Tampering

security
by [email protected] (The Hacker News) ·

Patch vulnerable Ruby gems and Go modules, audit GitHub Actions, and monitor for SSH persistence.

What to do now

Patch vulnerable Ruby gems and Go modules, audit GitHub Actions, and monitor for SSH persistence.

Summary

A new supply chain attack campaign has been observed using sleeper packages to deliver malicious payloads that enable credential theft, GitHub Actions tampering, and SSH persistence. The activity is attributed to the GitHub account “BufferZoneCorp,” which has published a set of repositories containing malicious Ruby gems and Go modules. The attackers embed credential‑stealing code within the gems, allowing them to harvest secrets from any project that imports them. In addition, the malicious modules tamper with GitHub Actions workflows, enabling the attackers to execute arbitrary code during CI/CD pipelines. The campaign also establishes SSH persistence by installing backdoors that survive system reboots. The use of sleeper packages demonstrates a new vector for supply chain compromise that bypasses traditional code review processes. Developers are advised to audit third‑party dependencies and monitor for unexpected changes in CI/CD configurations. The incident highlights the need for stricter dependency verification and runtime integrity checks.

Key changes

  • Sleeper packages used to deliver malicious payloads enabling credential theft.
  • Attack attributed to GitHub account “BufferZoneCorp.”
  • Malicious Ruby gems and Go modules embed credential‑stealing code.
  • Payloads tamper with GitHub Actions workflows for arbitrary code execution.
  • Attack establishes SSH persistence via backdoors.
  • Use of sleeper packages bypasses traditional code review.
  • Developers advised to audit third‑party dependencies.
  • Incident highlights need for stricter dependency verification and runtime integrity checks.

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting