{"id":963,"date":"2026-05-19T05:49:55","date_gmt":"2026-05-19T05:49:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=963"},"modified":"2026-05-19T05:49:55","modified_gmt":"2026-05-19T05:49:55","slug":"popular-github-action-tags-redirected-to-imposter-commit-to-steal-ci-cd-credentials","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=963","title":{"rendered":"Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI\/CD Credentials"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 19, 2026<\/span><\/span><span class=\"p-tags\">Software Security \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX4Ps2x9jSuwhi5sE-QjK_oEjLXgQW9e6EHx6W0G7qTqYTM3fZh1AQTyrgm2o-PFBeD9ryHnC6fDmK5MYKUzBjU_pJibTilnm1d99WSQkJux6PXXRydkYW5d15Ada-\/s1700-e365\/step.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, <b>actions-cool\/issues-helper<\/b>, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.<\/p>\n<p>\u00abEvery existing tag in the repository has been moved to point to an imposter commit that does not appear in the action&#8217;s normal commit history,\u00bb StepSecurity researcher Varun Sharma <a href=\"https:\/\/www.stepsecurity.io\/blog\/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials\">said<\/a>. \u00abThat commit contains malicious code that exfiltrates credentials from CI\/CD pipelines that run the action.\u00bb<\/p>\n<p>An <a href=\"https:\/\/www.chainguard.dev\/unchained\/what-the-fork-imposter-commits-in-github-actions-and-ci-cd\">imposter commit<\/a> refers to a deceptive software supply chain attack strategy in which malicious code is injected into a project by referencing a commit or tag that exists only in an adversary-controlled fork, rather than the original trusted repository. As a result, attackers can bypass standard Pull Request (PR) reviews and achieve arbitrary code execution.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The imposter commit, per the cybersecurity company, contains code that, upon being executed within a GitHub Actions runner, performs a series of actions &#8211;<\/p>\n<ul>\n<li>Downloads the Bun JavaScript runtime to the runner.<\/li>\n<li>Reads memory from the Runner.Worker process to extract credentials.<\/li>\n<li>Makes an outbound HTTPS call to an attacker-controlled domain (\u00abt.m-kosche[.]com\u00bb) to transmit the stolen data.<\/li>\n<\/ul>\n<p>StepSecurity said 15 tags associated with a second GitHub action, \u00abactions-cool\/maintain-one-comment\u00bb have also been compromised with the same functionality.<\/p>\n<p>GitHub has since <a href=\"https:\/\/github.com\/actions-cool\/maintain-one-comment\/\">disabled access to the repository<\/a> due to a \u00abviolation of GitHub&#8217;s terms of service.\u00bb It&#8217;s currently not known what led the Microsoft-owned subsidiary to this decision.<\/p>\n<p>Interestingly, the exfiltration domain \u00abt.m-kosche[.]com\u00bb has been observed in the latest wave of the Mini Shai-Hulud campaign targeting npm packages from the @antv ecosystem, indicating the two clusters of activity could be related.<\/p>\n<p>\u00abBecause every tag now resolves to malicious commits, any workflow that references the action by version pulls the malicious code on its next run,\u00bb StepSecurity said. \u00abOnly workflows pinned to a known-good full commit SHA are unaffected.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 19, 2026Software Security \/ Malware In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool\/issues-helper, to run malicious code that harvests&hellip;<\/p>\n","protected":false},"author":1,"featured_media":964,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1033,576,1717,446,71,1716,1714,1715,571,803],"class_list":["post-963","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-action","tag-cicd","tag-commit","tag-credentials","tag-github","tag-imposter","tag-popular","tag-redirected","tag-steal","tag-tags"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/963","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=963"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/963\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/964"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=963"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=963"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}