Original caption
Attackers are slipping malware into GitHub pull requests, hidden inside build configs. Every CI/CD pipeline opens these files automatically. Every developer triggers them the second they run npm run dev. By the time anyone notices, the whole team is compromised. Full breakdown at the link in bio. #cybersecurity #appsec #opensource #github #supplychainsecurity