A throwaway GitHub account compromised CNCF project Antrea's Jenkins infrastructure on May 2 by opening a malicious PR and firing /test-* slash-commands that detonated the workflow against PR-fork code with credentials in scope. The same operator ran parallel campaigns against at least seven other projects that week.










