Top 2026 Agentic AI Attack Detection — CI/CD Secrets Access and Automated Registry Publish (Supply-Chain Compromise)
Detects anomalous GitHub audit log activity indicative of a potential supply-chain compromise. The rule identifies workflows or automated entities (Bot/App) that access sensitive Action secrets followed by the publishing of packages to public registries like PyPI or npm. This activity can represent the precursor steps of token-theft-driven malicious package injection.
Sigma

