RE: https://infosec.exchange/@ryanc/117184229708073331
Oh look, neat new supply chain attack vector just dropped, potentially targeting every shell script ever! (Good intentions, but it's one github update away from letting attackers intercept and munge any set of arguments passed to a shell script anywhere. Neat proof of concept, now needs armouring against malicious modification.)