Collected research
One Supply Chain Attack to Rule Them All
A fork pull request can seize a non-ephemeral self-hosted GitHub Actions runner attached to a public repository: a one-character typo fix makes the attacker a contributor and clears the default approval gate, and the PR's own workflow file then runs code on the runner. Persistence there yields the write-scoped GITHUB_TOKEN and build secrets, here a path into GitHub's own runner images.
Record
- Researcher
- Adnan Khan and adnanthekhan
- Published by
- Adnan Khan - Security Research
- Date
- Topic
- Supply
In the archive
Related sources
- Research tool
- Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory
Tags
This page is the archive's own catalogue record. The research is the work of Adnan Khan and adnanthekhan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .