Stay tuned in 2023 for offensive supply-chain security https://github.com/kpcyrd/sh4d0wup 🦝

QT kpcyrd: The hardest part of writing a malicious container registry is how fragmented the ecosystem is. Each of these are valid responses when pulling a specific container image by tag.

GitHub - kpcyrd/sh4d0wup: Signing-key abuse and update exploitation framework

Signing-key abuse and update exploitation framework - GitHub - kpcyrd/sh4d0wup: Signing-key abuse and update exploitation framework

GitHub