logo

GitHub Actions artifacts found leaking auth tokens in popular projects

ID: a9b8334c-c0bb-52bd-8fbc-a8a5f298284e

STIX ID: report--a9b8334c-c0bb-52bd-8fbc-a8a5f298284e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Unit 42 found that GitHub Actions artifacts and misconfigured CI/CD workflows can leak GitHub authentication tokens and other sensitive secrets (by uploading .git directories, artifact logs, or environment-variable outputs), exposing many high-profile open-source projects; attackers could automatically find, download, and exploit these artifacts within token validity windows to access repositories, steal code, or inject malicious changes. The report lists affected projects, demonstrates attack flows and race-condition exploitation scenarios, and recommends sanitizing artifacts and logs, applying least-privilege tokens, and adjusting action defaults to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.