• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials

You are here: Home / General Cyber Security News / GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials
May 19, 2026

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.

“Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action’s normal commit history,” StepSecurity researcher Varun Sharma said. “That commit contains malicious code that exfiltrates credentials from CI/CD pipelines that run the action.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


An imposter commit refers to a deceptive software supply chain attack strategy in which malicious code is injected into a project by referencing a commit or tag that exists only in an adversary-controlled fork, rather than the original trusted repository. As a result, attackers can bypass standard Pull Request (PR) reviews and achieve arbitrary code execution.

Cybersecurity

The imposter commit, per the cybersecurity company, contains code that, upon being executed within a GitHub Actions runner, performs a series of actions –

  • Downloads the Bun JavaScript runtime to the runner.
  • Reads memory from the Runner.Worker process to extract credentials.
  • Makes an outbound HTTPS call to an attacker-controlled domain (“t.m-kosche[.]com”) to transmit the stolen data.

StepSecurity said 15 tags associated with a second GitHub action, “actions-cool/maintain-one-comment” have also been compromised with the same functionality.

GitHub has since disabled access to the repository due to a “violation of GitHub’s terms of service.” It’s currently not known what led the Microsoft-owned subsidiary to this decision.

Interestingly, the exfiltration domain “t.m-kosche[.]com” has been observed in the latest wave of the Mini Sha-Hulud campaign targeting npm packages from the @antv ecosystem, indicating the two clusters of activity could be related.

“Because every tag now resolves to malicious commits, any workflow that references the action by version pulls the malicious code on its next run,” StepSecurity said. “Only workflows pinned to a known-good full commit SHA are unaffected.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «mini shai hulud pushes malicious antv npm packages via compromised maintainer Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials
  • Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
  • INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
  • ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
  • How to Reduce Phishing Exposure Before It Turns into Business Disruption
  • Developer Workstations Are Now Part of the Software Supply Chain
  • Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
  • Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
  • Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
  • MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Copyright © TheCyberSecurity.News, All Rights Reserved.