Web Hack List

Collected research

The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree

GitHub Actions can depend on other actions through action.yml and through the workflows that build them, forming a dependency tree mapped here across the Marketplace. Code running in a job can read the runner's memory to recover every secret in that job, including a GITHUB_TOKEN never referenced, then use its write access to infect dependent action repositories - a worm. Repojacking, npm account hijacking and command injection supply the foothold.

Record

Researcher
@PaloAltoNtwks and Asi Greenholts
Published by
Palo Alto Networks Blog
Date
Topic
Supply

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @PaloAltoNtwks and Asi Greenholts, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .