Self-propagating supply chain worms (Shai-Hulud/Mini Shai-Hulud)
OIDC token extraction from GitHub Actions runner memory to forge SLSA provenance
GitHub Actions cache poisoning
Abuse of exposed cloud-native APIs (Docker, Ray, Redis)
IDE extension abuse (VS Code extensions) for credential theft
Credential stealing via SANDCLOCK and FIRESCALE malware
Partnership with Ransomware-as-a-Service (RaaS) operators (Vect)
Git tag manipulation and workflow injection
AI-driven payload generation and prompt injection to evade scanners