Xygeni GitHub Action Compromised Via Tag Poison
ID: a02d8f38-b3d7-59b0-9378-f36480f3869e
STIX ID: report--a02d8f38-b3d7-59b0-9378-f36480f3869e
Feed Name: Dark Reading
An unidentified threat actor poisoned a mutable Git tag (v5) in Xygeni's official GitHub Action to point at a commit containing a C2 reverse shell. The attacker leveraged a compromised maintainer personal access token and a GitHub App private key to create PRs and pivot to tag-based delivery; any workflows using xygeni/xygeni-action@v5 from March 3–10 potentially executed arbitrary commands on CI runners (exposing GITHUB_TOKEN, repo secrets, and source). Xygeni removed the tag after community reports, concluded the GitHub App key had overly broad permissions, and recommended immutability, signed commits, permission hardening, pinning to commit SHAs, CI log audits, and secret rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
