logo

ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts

ID: cb32592d-28f2-578b-9a72-9332d0d2a269

STIX ID: report--cb32592d-28f2-578b-9a72-9332d0d2a269

Feed Name: Palo Alto Networks Unit 42

Threat Score
80/100

Date Published: 2024-08-13

Date Updated: 2026-04-28

Author: Yaron Avital

...
...

This report from Palo Alto Networks details research showing that GitHub Actions build artifacts can unintentionally contain sensitive tokens (GITHUB_TOKEN and ACTIONS_RUNTIME_TOKEN), which attackers can extract—within token expiration windows—to push unauthorized code, replace artifacts (enabling remote code execution), or access cloud/GitHub secrets; the author automated discovery across popular public projects, demonstrated PoC exploitation against multiple high-profile repositories, reported findings to maintainers, and provided mitigation guidance including a secure artifact upload action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.