Best Detection of 2026 Series: Autonomous Supply-Chain Compromise via CI/CD Toke
Detects anomalous activity in a CI/CD environment where a runner process accesses sensitive credential files (such as PyPI tokens or GitHub secrets) followed closely by a network connection to public package registry domains, potentially indicating a supply-chain compromise where stolen credentials are used to publish malicious packages.
YARA-L

