← Home
#github-actions
19 stories tagged.
The Worm That Learned to Sign Itself: Shai Hulud's Eight-Month npm Supply Chain Rampage — A Full Post-Mortem
12 min · 0 sources
The CI/CD Takeover: How GitHub Actions Script Injection Turned elementary-data Into a 1.1M-Download Infostealer
9 min · 0 sources
Comment and Control: How a Single GitHub PR Title Stole API Keys from Claude Code, Gemini CLI, and GitHub Copilot
11 min · 0 sources
The Worm That Eats Your Vault: Shai-Hulud's Bitwarden CLI Attack and the Definitive CI/CD Secrets Defense Playbook
11 min · 0 sources
Pipeline Poisoners: How BufferZoneCorp Weaponized Ruby Gems and Go Modules to Own CI/CD at the Build Stage
10 min · 0 sources
The 11-Hour Data Heist: How a GitHub Actions PR Comment Poisoned 1.1M-Download PyPI Package elementary-data
9 min · 0 sources
The 90-Minute Window: How Shai-Hulud's Third Coming Weaponized Bitwarden's Own CI Pipeline Against 250,000 Developers
10 min · 0 sources
The Data Pipeline That Became a Drain: How elementary-data's CI/CD Was Weaponized to Steal 1.1M-Download-Scale Cloud Credentials
9 min · 0 sources
The Comment That Poisoned a Million Pipelines: elementary-data's GitHub Actions Script Injection and the Rise of CI-Native Supply Chain Attacks
10 min · 0 sources
The Pipeline Is the Payload: How GitHub Actions Script Injection Turned elementary-data Into a Credential Harvester for 1.1 Million Developers
11 min · 0 sources
The Package That Waited: BufferZoneCorp's Sleeper Gems and Go Modules Reveal a New CI Pipeline Takeover Playbook
9 min · 0 sources
Shai-Hulud: The Third Coming — How TeamPCP Turned Trivy Into a Master Key, Checkmarx Into a Staging Ground, and Bitwarden CLI Into a Self-Propagating CI/CD Worm
10 min · 0 sources
The Pipeline Is the Weapon: How elementary-data's GitHub Actions Injection Turned 1.1 Million PyPI Installs Into a Credential Vacuum
11 min · 0 sources
The Sleeper Cluster Wakes: BufferZoneCorp + TeamPCP's Cross-Ecosystem Supply Chain Wave (Ruby, Go, npm, GitHub Actions)
11 min · 0 sources
The CI/CD Killswitch: GitHub Actions' Systemic Design Flaws and the Eighteen-Month Chain from spotbugs to Bitwarden
10 min · 0 sources
Comment and Control: How a PR Title Became a C2 Channel and Drained Secrets from Three AI Coding Agents
10 min · 0 sources
The Trust Ladder: How TeamPCP Climbed From Security Scanners to Password Managers — Six Weeks of Supply Chain Escalation, Post-Mortem
10 min · 0 sources
The Scanner That Got Scanned: Trivy's Double Breach, Hackerbot-Claw, and the AI-Automated Future of GitHub Actions Supply Chain Attacks
10 min · 0 sources
The 48-Hour Siege: How Three Simultaneous Supply Chain Campaigns Turned npm, PyPI, and Docker Hub Into Credential Factories
12 min · 0 sources