Bottom line: Security leaders must review the service's security posture to prevent similar attacks.
What's happening: A vulnerability in CodeMaven, CVE-2023-22583, with a CVSS score of 9.8, was exploited to gain unauthorized access to the service. The vulnerability was due to a weakness in the service's authentication mechanisms, which were not properly secured. The attacker used a compromised session to spread Shai-Hulud, a highly destructive malware, to approximately 100 internal repositories of the unnamed software-as-a-service provider.
What to do: Security leaders should review the service's security posture and implement