GitHub Actions artifacts found leaking auth tokens in popular projects
ID: a9b8334c-c0bb-52bd-8fbc-a8a5f298284e
STIX ID: report--a9b8334c-c0bb-52bd-8fbc-a8a5f298284e
Feed Name: Bleeping Computer
Unit 42 found that GitHub Actions artifacts and misconfigured CI/CD workflows can leak GitHub authentication tokens and other sensitive secrets (by uploading .git directories, artifact logs, or environment-variable outputs), exposing many high-profile open-source projects; attackers could automatically find, download, and exploit these artifacts within token validity windows to access repositories, steal code, or inject malicious changes. The report lists affected projects, demonstrates attack flows and race-condition exploitation scenarios, and recommends sanitizing artifacts and logs, applying least-privilege tokens, and adjusting action defaults to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
