Skip to main content

Threats Tagged 'github-actions'

View all threats tagged with 'github-actions'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: github-actions

Threats Tagged 'github-actions'

Click on any threat for detailed analysis and mitigation recommendations

Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a fork, whose branch name contains shell metacharacters, and the workflow automatically interprets those characters as commands without maintainer interaction. The commands execute on a runner with base-repository secrets and a write-scoped GITHUB_TOKEN, allowing arbitrary command execution, secret or token exfiltration, unauthorized pushes, and other token abuse. The fixed implementations in src/index.ts and src/conflibot.ts use execFile or spawn argument arrays, and the v2 line also uses numeric pull-request refs rather than branch names. This issue is fixed in versions 1.2.1 and 2.0.0.

Join the discussion

A new Mini Shai-Hulud worm variant named Trinitite was detected targeting the npm package @7nohe/openapi-react-query-codegen. The attacker exploited a GitHub workflow vulnerability allowing any user to trigger npm publish via pull-request comments, resulting in rapid publication of malicious package versions. The worm uses obfuscation techniques to execute even when scripts are disabled, steals credentials from multiple developer and cloud platforms, and exfiltrates data via GitHub commits. It establishes persistence through systemd services and includes a destructive token revoke mechanism that can wipe user directories. This campaign is linked to the TeamPCP threat actor and appeared shortly after arrests of related suspects in Australia.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: github-actions
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses