Fake GitHub CI Update Steals Secrets and Tokens
ID: 962f3eab-4431-5702-bfac-ee2e4bb22153
STIX ID: report--962f3eab-4431-5702-bfac-ee2e4bb22153
Feed Name: GBHackers
Threat Score
**Executive Summary:** An automated campaign (active March–April 2026) abused GitHub Actions' pull_request_target trigger by submitting hundreds of malicious PRs that injected CI-relevant payloads to exfiltrate GITHUB_TOKEN and other secrets, probe cloud metadata, and publish malicious npm package versions; the attacker adapted through phases from simple scripts to AI‑generated, repository‑aware payloads and successfully compromised at least two npm packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
