logo

Fake GitHub CI Update Steals Secrets and Tokens

ID: 962f3eab-4431-5702-bfac-ee2e4bb22153

STIX ID: report--962f3eab-4431-5702-bfac-ee2e4bb22153

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-06

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

**Executive Summary:** An automated campaign (active March–April 2026) abused GitHub Actions' pull_request_target trigger by submitting hundreds of malicious PRs that injected CI-relevant payloads to exfiltrate GITHUB_TOKEN and other secrets, probe cloud metadata, and publish malicious npm package versions; the attacker adapted through phases from simple scripts to AI‑generated, repository‑aware payloads and successfully compromised at least two npm packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.