New GitHub Actions Attack Chain Uses Fake CI Updates to Exfiltrate Secrets and Tokens
ID: edcdb5ca-1407-5d95-b6bf-e57b0153e5f1
STIX ID: report--edcdb5ca-1407-5d95-b6bf-e57b0153e5f1
Feed Name: cybersecurityNews.com
**Executive summary:** The "prt-scan" campaign actively targeted GitHub repositories by submitting malicious pull requests that abuse the pull_request_target GitHub Actions trigger to run in the base-repository context and exfiltrate repository and cloud secrets (GITHUB_TOKEN, AWS/Azure/GCP metadata credentials, API tokens). Researchers traced over 500 malicious PRs (with a surge of ~475 in 26 hours), confirmed theft of AWS, Cloudflare, and Netlify tokens, and compromise of two npm packages across 106 versions; recommended mitigations include restricting pull_request_target to approved contributors, enforcing contributor approval gates, applying actor- or path-based conditions, and rotating any exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
