@koh
From personal security auditing, I still don’t know where the base attack came from although I do believe it to be relevant to open claw or npm pipelines . It was only a GitHub token that submitted malware to other repositories that I noticed 🤪
Luckily we have sollid mods and don’t store keys 👏