Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Actions Compromised to Steal CI/CD Credentials

GitHub Actions Compromised to Steal CI/CD Credentials

Posted on May 19, 2026 By CWS

In a recent cyberattack targeting software supply chains, malicious actors have compromised a popular GitHub Actions workflow, known as actions-cool/issues-helper. This breach resulted in the execution of harmful code, aimed at gathering sensitive credentials and redirecting them to a server managed by attackers.

According to Varun Sharma, a researcher at StepSecurity, the breach involved redirecting all existing tags in the repository to an imposter commit. This commit, which isn’t part of the action’s original commit history, includes code that siphons off credentials from CI/CD pipelines using this action.

Understanding the Imposter Commit Strategy

An imposter commit represents a sophisticated software supply chain attack method. By injecting malicious code into a project, attackers use a commit or tag existing only in a fork they control, circumventing customary Pull Request (PR) reviews. This tactic allows them to execute arbitrary code without detection.

The malicious code embedded in the imposter commit initiates several actions once executed in a GitHub Actions runner. It downloads the Bun JavaScript runtime, extracts credentials from the Runner.Worker process, and sends the stolen data to a domain controlled by the attackers.

Extent of the Compromise

StepSecurity has reported that not only was the actions-cool/issues-helper affected, but 15 tags of another GitHub action, “actions-cool/maintain-one-comment,” were also compromised with similar malicious functionality. Due to these violations, GitHub has disabled access to the affected repository, though the exact reasons for this decision by the Microsoft-owned platform remain unclear.

Interestingly, the domain used for data exfiltration has connections to the ongoing Mini Shai-Hulud campaign, targeting npm packages from the @antv ecosystem. This suggests a possible link between the two malicious activities.

Impact on Workflows and Security Recommendations

As StepSecurity noted, any workflows referencing the compromised action by version will automatically pull in the malicious code. However, workflows pinned to a specific, verified commit SHA will remain secure from this threat.

This incident underscores the importance of vigilance in software development environments, especially when using third-party actions in CI/CD pipelines. Developers are advised to routinely audit their workflows, ensure dependencies are secure, and consider pinning actions to known-safe commits.

Going forward, organizations must strengthen their security protocols to mitigate such risks and protect their software supply chains from similar attacks.

The Hacker News Tags:actions-cool, CI/CD, credentials theft, Cybersecurity, GitHub, GitHub actions, imposter commit, JavaScript runtime, Malware, Mini Shai-Hulud, npm packages, security breach, software supply chain, StepSecurity

Post navigation

Previous Post: Mythos Preview AI Revolutionizes Vulnerability Exploitation
Next Post: Hackers Exploit Microsoft Entra ID to Access Sensitive Data

Related Posts

Critical Flaw in Terrarium Sandbox Allows Code Execution Critical Flaw in Terrarium Sandbox Allows Code Execution The Hacker News
Kali Linux Update, Chrome Threats & Security Risks Unveiled Kali Linux Update, Chrome Threats & Security Risks Unveiled The Hacker News
Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware The Hacker News
EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware The Hacker News
GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security GitHub Mandates 2FA and Short-Lived Tokens to Strengthen npm Supply Chain Security The Hacker News
Shifting from Monitoring Alerts to Measuring Risk Shifting from Monitoring Alerts to Measuring Risk The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Alerts Users to Global Spyware Threats
  • CTM360 Exposes Over 3,000 Phishing URLs in Job Scams
  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Alerts Users to Global Spyware Threats
  • CTM360 Exposes Over 3,000 Phishing URLs in Job Scams
  • Chrome DevTools Enables Session Hijacking in Windows
  • Mustang Panda’s Enhanced CoolClient and Rootkit Tactics
  • Cavern Framework Evolves with New DNS and Google Apps Integration

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark