GitHub Actions Tags Redirected to Steal CI/CD Keys
In a concerning development, threat actors have targeted GitHub Actions tags, redirecting them to unauthorized commit points as part of a sophisticated software supply chain attack. This breach specifically involves the popular GitHub Actions workflow, actions-cool/issues-helper, which attackers have manipulated to execute malicious code. This code is designed to harvest sensitive CI/CD credentials and transmit […]
