Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Nx Console 18.95.0 compromised and VS Code developers targeted by Credential Stealer

Who turned the lights on? The modern impact of light pollution on the night sky

Why European fusion must move beyond research to delivery

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Popular GitHub action tag redirects to fraudsters stealing CI/CD credentials
Identity

Popular GitHub action tag redirects to fraudsters stealing CI/CD credentials

By May 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 19, 2026Software security/malware

In yet another software supply chain attack, threat actors compromised the popular GitHub Actions workflow, actions-cool/issues-helper, collected sensitive credentials, and executed malicious code that was leaked to attacker-controlled servers.

“All existing tags in the repository were moved to point to the impostor commit, which does not appear in the action’s normal commit history,” said Varun Sharma, a researcher at StepSecurity. “That commit contains malicious code that extracts credentials from the CI/CD pipeline that performs the action.”

Impostor commits refer to a deceptive software supply chain attack strategy that injects malicious code into a project by referencing commits or tags that exist only in an adversary-controlled fork rather than in the original trusted repository. As a result, an attacker could bypass standard pull request (PR) reviews and execute arbitrary code.

According to the cybersecurity firm, the imposter’s commit contains code that performs a series of actions when executed within the GitHub Actions runner.

Download the Bun JavaScript runtime to your runner. Reads memory from the Runner.Worker process and extracts credentials. Makes outbound HTTPS calls to an attacker-controlled domain (‘tm-kosche’).[.]com) to send the stolen data.

According to StepSecurity, 15 tags associated with a second GitHub action, “actions-cool/maintain-one-comment,” were also compromised with the same feature.

GitHub subsequently disabled access to the repository for “violation of GitHub’s Terms of Service.” It is currently unclear why the Microsoft-owned subsidiary came to this decision.

Interestingly, the leaked domain “tm-kosche”[.]com” has been observed in the latest wave of Mini Shai-Hulud campaigns targeting npm packages in the @antv ecosystem, indicating that the two clusters of activity may be related.

“Every tag now resolves to a malicious commit, so any workflow that references an action by version will pull the malicious code the next time it runs,” StepSecurity said. “Only workflows that are pinned to a healthy full-commit SHA are not affected.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMini Shai-Hulud pushes malicious AntV npm packages via compromised maintainer account
Next Article Theo Baker spent four years researching Stanford. Before he left, this is what he found.

Related Posts

Nx Console 18.95.0 compromised and VS Code developers targeted by Credential Stealer

May 19, 2026

Mini Shai-Hulud pushes malicious AntV npm packages via compromised maintainer account

May 19, 2026

Interpol’s Operation Ramz disrupts MENA cybercrime network, arrests 201 people

May 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Nx Console 18.95.0 compromised and VS Code developers targeted by Credential Stealer

Who turned the lights on? The modern impact of light pollution on the night sky

Why European fusion must move beyond research to delivery

How NCP_WIDERA.NET supports applicants and national contacts

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.