For the 2nd time in weeks, Microsoft packages laced with credential stealer
…Security firm Cloudsmith said the malware harvests OIDC (OpenID-Connect) token credentials that are used in SLSA (Supply-chain Levels for Software Artifacts) provenance attestation , a method for providing cryptographically signed guarantees…