On August 4, 2025, the AWS GitHub Action `configure-aws-credentials` had its v4.3.0 release tag deleted and recreated pointing to a different commit after a critical bug was discovered. StepSecurity's Artifact Monitor flagged this tag movement within minutes as suspicious — the same pattern used in real supply chain attacks

9m read timeFrom stepsecurity.io
Post cover image
Table of contents
What Happened: Tag v4.3.0 Created, Unreleased, and RecreatedWhy Tag Movements Are Rare Red Flags and When They’re MaliciousAutomatic Detection by StepSecurity’s Artifact MonitorConclusion: Monitor Your Releases and Stay Ahead of Threats

Sort: