Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Compromised to Steal CI/CD Credentials

GitHub Actions Compromised to Steal CI/CD Credentials

Posted on May 19, 2026 By CWS

In a recent cyberattack targeting software supply chains, malicious actors have compromised a popular GitHub Actions workflow, known as actions-cool/issues-helper. This breach resulted in the execution of harmful code, aimed at gathering sensitive credentials and redirecting them to a server managed by attackers.

According to Varun Sharma, a researcher at StepSecurity, the breach involved redirecting all existing tags in the repository to an imposter commit. This commit, which isn’t part of the action’s original commit history, includes code that siphons off credentials from CI/CD pipelines using this action.

Understanding the Imposter Commit Strategy

An imposter commit represents a sophisticated software supply chain attack method. By injecting malicious code into a project, attackers use a commit or tag existing only in a fork they control, circumventing customary Pull Request (PR) reviews. This tactic allows them to execute arbitrary code without detection.

The malicious code embedded in the imposter commit initiates several actions once executed in a GitHub Actions runner. It downloads the Bun JavaScript runtime, extracts credentials from the Runner.Worker process, and sends the stolen data to a domain controlled by the attackers.

Extent of the Compromise

StepSecurity has reported that not only was the actions-cool/issues-helper affected, but 15 tags of another GitHub action, “actions-cool/maintain-one-comment,” were also compromised with similar malicious functionality. Due to these violations, GitHub has disabled access to the affected repository, though the exact reasons for this decision by the Microsoft-owned platform remain unclear.

Interestingly, the domain used for data exfiltration has connections to the ongoing Mini Shai-Hulud campaign, targeting npm packages from the @antv ecosystem. This suggests a possible link between the two malicious activities.

Impact on Workflows and Security Recommendations

As StepSecurity noted, any workflows referencing the compromised action by version will automatically pull in the malicious code. However, workflows pinned to a specific, verified commit SHA will remain secure from this threat.

This incident underscores the importance of vigilance in software development environments, especially when using third-party actions in CI/CD pipelines. Developers are advised to routinely audit their workflows, ensure dependencies are secure, and consider pinning actions to known-safe commits.

Going forward, organizations must strengthen their security protocols to mitigate such risks and protect their software supply chains from similar attacks.

The Hacker News Tags:actions-cool, CI/CD, credentials theft, Cybersecurity, GitHub, GitHub actions, imposter commit, JavaScript runtime, Malware, Mini Shai-Hulud, npm packages, security breach, software supply chain, StepSecurity

Post navigation

Previous Post: Mythos Preview AI Revolutionizes Vulnerability Exploitation
Next Post: Hackers Exploit Microsoft Entra ID to Access Sensitive Data

Related Posts

Microsoft Expands Sentinel Into Agentic Security Platform With Unified Data Lake Microsoft Expands Sentinel Into Agentic Security Platform With Unified Data Lake The Hacker News
Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access Hackers Target ICTBroadcast Servers via Cookie Exploit to Gain Remote Shell Access The Hacker News
New Brazilian Malware Targets Financial Platforms New Brazilian Malware Targets Financial Platforms The Hacker News
Google Fixes Chrome 0-Days, AWS Breach, AI Security Risks Google Fixes Chrome 0-Days, AWS Breach, AI Security Risks The Hacker News
How CISOs Can Drive Effective AI Governance How CISOs Can Drive Effective AI Governance The Hacker News
New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware
  • OpenAI Dismisses Safety Team Members Over Data Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark