HIGHSupply Chain
Verified
Global

GitHub Actions Supply Chain Attack Injects Malware Into CI/CD Pipelines

·Source: GitHub Security Advisory

Updated:

Executive Summary

Compromised GitHub Action used by 23,000+ repositories injects credential-stealing code into CI/CD pipelines. Broad exposure across enterprise repositories.

Analysis

A popular GitHub Action with 23,000+ repository users was compromised after the maintainer account was hijacked. The malicious version exfiltrates CI/CD secrets including cloud credentials, NPM tokens, and Docker registry passwords during pipeline execution. GitHub has revoked the compromised versions and is notifying affected organizations. The incident highlights ongoing risks in CI/CD supply chain security.

Timeline

Discovered
Mar 2, 2026
Published
Mar 2, 2026
Source Attribution

Originally published by GitHub Security Advisory on Mar 2, 2026. Verified by: GitHub, CISA.

Related Threats

LOWSupply Chain

OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines

OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment standards. GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight

CSO Online
MEDIUMSupply Chain

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

The Hacker News
CRITICALSupply Chain

Lantronix G520 Series Cellular Gateway

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.</strong></p> <p>The following versions of Lantronix G520 Series Cellular Gateway are affecte

CVE-2026-84409CVE-2026-91191
CISA Advisories