The attack exploited a Pwn request targeting GitHub Actions workflow misconfiguration, GitHub Actions cache poisoning executed eight hours before the release workflow ran, and OIDC token extraction from runner process memory to steal authentication tokens before the legitimate publish step.