logo

Supply Chain Attack Targets GitHub Actions via Malicious Ruby Gems and Go Modules

ID: 89c3f271-970f-5104-9885-f469542e803c

STIX ID: report--89c3f271-970f-5104-9885-f469542e803c

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: AnuPriya

...
...

A supply-chain campaign linked to a GitHub account (BufferZoneCorp) distributes malicious Ruby gems (using deceptive names like "knot-...") and Go modules (e.g., github.com/BufferZoneCorp/go-metrics-sdk) that execute during install/initialization to exfiltrate SSH keys, AWS credentials, and GitHub configuration, manipulate CI workflows and dependency resolution (including disabling checksum checks), and establish persistence by appending an SSH public key to authorized_keys; organizations are advised to audit dependencies, rotate exposed credentials, and review CI/CD workflows and environment variables.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.