
Microsoft’s Yossi Weizman and Echo’s Mor Weinberger showed that recent supply chain attacks such as Shai-Hulud, Trivy, and Megalodon repeatedly used the same patterns: forged commit identities, poisoned tags, workflow abuse, OIDC token misuse, and attempts at evidence erasure.
These hallmarks of potential malfeasance can be turned into behavioural detections using GitHub webhooks, APIs, and Git metadata, the researchers explained during their presentation.
They released an open-source tool called GitHub Threat Detector, offering 30 built-in detection rules, to accompany their talk. GitHub Threat Detector follows an EDR-like pipeline, but ought to be viewed as a work in progress, they noted; its current drawbacks include possibly disabled webhooks, rate-limited APIs and an absence of real time inspection.
