Web Hack List

Preliminary research

Angular compromise through dev infra: GitHub Actions cache poisoning as a vulnerability class

Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

A pull_request_target workflow in angular/dev-infra interpolated github.head_ref into a run step, so a branch name executed commands even though the token was read-only and no secrets were present. The payload flooded the Actions cache past 10 GB to force immediate LRU eviction, then claimed the evicted node_modules keys; a scheduled Renovate job restored the poisoned entry and leaked a bot PAT, which could force-push an imposter actions/checkout SHA into an already-approved bot PR.

Record

Document
Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning
Researcher
Adnan Khan and adnanthekhan
Published by
Adnan Khan - Security Research
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adnan Khan and adnanthekhan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .