A GitHub token leak could have put the entire Python language at risk

What if the Python programming language was malicious? It would be the most devastating supply chain attack in human history, but it almost happened after an important GitHub token was accidentally leaked.

JFrog cybersecurity researchers recently discovered a GitHub personal access token in a public Docker container hosted on Docker Hub, which granted elevated access to GitHub repositories for the Python language, Python Package Index (PyPI), and Python Software Foundation (PSF).

scroll to top