Malicious GitHub Action Steals Workflow Credentials In Supply Chain Attack
ID: 93be5c4a-e394-5064-b7a1-adff17498595
STIX ID: report--93be5c4a-e394-5064-b7a1-adff17498595
Feed Name: Cyber Press
Security researchers uncovered a supply-chain attack on the actions-cool GitHub Actions (notably actions-cool/issues-helper) where repository tags were repointed to dangling imposter commits that deploy a payload which downloads the bun runtime, spawns Python processes to scrape runner memory (/proc/*/mem) for decrypted secrets, and exfiltrates them to an attacker-controlled domain (t.m-kosche.com). The attack produced dozens of automated imposter commits within minutes; the report lists IOCs (compromised action names, exfiltration domain, bun path, target process memory path) and describes mitigations such as automated workflow cancellation and global blocklists to prevent execution and outbound exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
