supply-chain
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials
High
Summary
A GitHub Actions workflow, actions-cool/issues-helper, was compromised through an imposter commit attack, allowing threat actors to steal CI/CD credentials from running workflows. The attack leveraged malicious code injected via manipulated GitHub Action tags, redirecting users to a server for data exfiltration. This highlights a significant vulnerability in the software supply chain and the potential for unauthorized code execution.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
