logo

Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials

ID: 1fc4be1a-4d10-5852-a4e0-15659033da0e

STIX ID: report--1fc4be1a-4d10-5852-a4e0-15659033da0e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: [email protected] (The Hacker News)

...
...

A supply‑chain compromise of the GitHub Actions workflows actions-cool/issues-helper and actions-cool/maintain-one-comment used 'imposter commits' in an adversary-controlled fork to inject malicious code that downloads the Bun runtime, reads memory from the Runner.Worker process to harvest CI/CD credentials, and exfiltrates them to t.m-kosche.com; the exfiltration domain ties this activity to the Mini Shai-Hulud campaign targeting @antv npm packages, and GitHub has disabled access to the repository (workflows pinned to full commit SHAs remain unaffected).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.