Supply Chain Compromise via GitHub Actions

Reported 14 Jul 2026 by otx · Severity: medium

On July 14, 2026, an attacker exploited a misconfigured GitHub Actions workflow in the AsyncAPI generator repository through a 'pwn request' vulnerability. The attacker opened 37 pull requests, with one containing obfuscated JavaScript that exfiltrated a highly privileged Persona