Other nomination
The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree
GitHub Actions can depend on other actions through action.yml and through the workflows that build them, forming a dependency tree mapped here across the Marketplace. Code running in a job can read the runner's memory to recover every secret in that job, including a GITHUB_TOKEN never referenced, then use its write access to infect dependent action repositories - a worm. Repojacking, npm account hijacking and command injection supply the foothold.
Record
- Researcher
- @PaloAltoNtwks and Asi Greenholts
- Published by
- Palo Alto Networks Blog
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @PaloAltoNtwks and Asi Greenholts, first published at the original source. Preserved copies are kept so the citation survives its host.