Threats Tagged 'mal-2026-17319'
View all threats tagged with 'mal-2026-17319'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-17319'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (cae53348f8261653938b39ae3cb79101baff666c4216ecaeb635e34b42ba8293) At install time, setup.py harvests the installer's GitHub credential and uses it to modify the installer's own repository. The script reads `$GITHUB_WORKSPACE/.git/config`, regexes the `extraheader = AUTHORIZATION: basic <b64>` line that actions/checkout injects for the running job, base64-decodes it to recover the token, and also reads `GITHUB_TOKEN` from the environment. Using that token as `x-access-token`, it clones the installer's repository, creates branch `feature/ci-health-check`, writes `.github/workflows/ci-health-check.yml`, commits as `github-actions[bot]` with message `Add CI health check`, and pushes via git (with a REST-API fallback), explicitly bypassing the API restriction that protects workflow files. This plants a persistent, attacker-controlled GitHub Actions workflow in the installer's repository that will execute on future pushes to the planted branch. The shipped Python module `bfox_build_utils.py` is a two-line stub containing only `VERSION = "1.0.997"`; the package's advertised purpose (`Build utilities.`) and the innocuous naming of the branch, commit, and bot identity are cover for the credential theft and workflow-injection payload in setup.py. Join the discussion | GCVE Database | 09/30/2026, 03:04:36 UTC Added: 09/30/2026, 10:01:11 UTC |
Showing 1 to 1 of 1 result