Web Hack List

Collected research

One Supply Chain Attack to Rule Them All

A fork pull request can seize a non-ephemeral self-hosted GitHub Actions runner attached to a public repository: a one-character typo fix makes the attacker a contributor and clears the default approval gate, and the PR's own workflow file then runs code on the runner. Persistence there yields the write-scoped GITHUB_TOKEN and build secrets, here a path into GitHub's own runner images.

Record

Researcher
Adnan Khan and adnanthekhan
Published by
Adnan Khan - Security Research
Date
Topic
Supply

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adnan Khan and adnanthekhan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .