Web Hack List

Preliminary research

Angular compromise through dev infra: GitHub Actions cache poisoning as a vulnerability class

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

A pull_request_target workflow in angular/dev-infra interpolated github.head_ref into a run step, so a branch name executed commands even though the token was read-only and no secrets were present. The payload flooded the Actions cache past 10 GB to force immediate LRU eviction, then claimed the evicted node_modules keys; a scheduled Renovate job restored the poisoned entry and leaked a bot PAT, which could force-push an imposter actions/checkout SHA into an already-approved bot PR.

Record

Researcher
Adnan Khan and adnanthekhan
Published by
Adnan Khan - Security Research
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adnan Khan and adnanthekhan, first published at the original source. Preserved copies are kept so the citation survives its host.