216.73.217.22

Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

· Published 20/03/2026 09:51 · Modified 20/03/2026 21:18

Export JSON

Essential information

Published
20/03/2026 09:51
Modified
20/03/2026 21:18
Tags
2026-03-20 ci/cd credential-theft exfiltration github actions infostealer supply chain attack teampcp cloud stealer trivy typosquat
Related entities
2 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 1 others

Description

A new targeting has compromised 75 out of 76 version tags in the aquasecurity/-action GitHub repository. The attacker force-pushed these tags to serve malicious payloads, effectively turning trusted version references into a distribution mechanism for an . The malicious code executes within runners, targeting sensitive data in environments. It harvests secrets from runner process memory and the filesystem, encrypts the collected data, and exfiltrates it to an attacker-controlled endpoint or a fallback GitHub-based channel. The attack's scope is significant, potentially affecting over 10,000 workflow files on GitHub referencing this action.

External references