Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ci-cd (16 articles)Clear

Compromised GitHub Actions came back online still executing Mini Shai-Hulud credential malware

Socket reported that two GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were disabled a second time after their repositories became accessible again on September 16, months after being compromised in the May Mini Shai-Hulud campaign. When the repositories returned, their release tags were not cleaned up and still pointed to the malicious content introduced on May 18, so any workflow referencing either action by a version tag resumed downloading and executing the payload on its next run. The original May 18 compromise ran code that harvested credentials from CI/CD pipelines and exfiltrated them, activity linked to the Mini Shai-Hulud cluster through a shared exfiltration domain. GitHub has again disabled both repositories.

Check
Audit workflows for references to the two actions-cool actions, pin actions to trusted commit hashes, and rotate any CI/CD secrets exposed since September 16.
Affected
Pipelines referencing the affected actions-cool actions by version tag re-ran the May 18 payload after September 16, harvesting and exfiltrating CI/CD credentials.
Fix
Remove or repin the actions to vetted commits, rotate pipeline secrets, and prefer commit-hash pinning over mutable version tags for third-party actions.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.

Attackers exploit a critical JFrog Artifactory flaw to mint admin tokens

Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.

Check
Patch self-managed JFrog Artifactory to 7.161.20 or later immediately, prioritizing internet-exposed instances, then inspect audit logs for unexpected admin tokens, user enumeration, and any changes to hosted artifacts.
Affected
Organizations running self-managed JFrog Artifactory in default configuration (CVE-2026-82329); an unauthenticated attacker with network access can gain admin, mint tokens, harvest credentials, and tamper with the supply chain, and exploitation is active.
Fix
Patch now, rotate Artifactory credentials and tokens, review hosted packages and build pipelines for tampering, restrict network exposure of the service, and treat any exposed unpatched instance as a supply-chain compromise.

GitHub issue title let an AI agent hijack Snowflake CI and steal a token

Researchers at Wiz found that a public Snowflake code repository could be hijacked through nothing more than a crafted GitHub issue title. A workflow that ran when issues were opened dropped the attacker-controlled title straight into a command, so an unauthenticated user could run code on the GitHub Actions runner and steal a Jira API token used by the automation. The notable twist is how the bug arrived: it was introduced days earlier by an AI tool meant to fix security issues, and an AI code reviewer approved the change. Snowflake fixed it by passing the title safely as an argument rather than expanding it into a command.

Check
Audit GitHub Actions workflows that run on untrusted input like issue titles or pull requests, and never interpolate that input directly into shell commands; pass it as environment variables or arguments.
Affected
Repositories whose workflows trigger on issues or pull requests and interpolate attacker-controlled text into commands; an unauthenticated user can run code on the runner and steal the secrets the workflow holds.
Fix
Sanitize untrusted workflow input, minimize the secrets and permissions each workflow can access, and do not assume AI-generated or AI-reviewed code is safe, since automated fixes and reviews miss injection flaws.

A single GitHub issue could reach CI secrets across major AI coding agents

Novee Security showed at Black Hat that a GitHub issue opened by an account with no repository access could reach the CI runners behind major AI coding agents in their default configurations, tested against Claude Code, Gemini CLI, and Codex. The strongest, a Gemini CLI container-launcher command injection scored 10.0, runs code on the CI host before the sandbox starts. In Claude Code, a validator that stripped quoted text let a payload in a Git flag reach the runner, and a separate flaw leaked an API key through a download counter. Untrusted issue content reaching an agent that holds secrets and tools in the same runtime is the shared weakness.

Check
Update Gemini CLI to 0.39.1 and Claude Code to 2.1.163, and review any workflow where an AI agent runs automatically on issues or pull requests from untrusted users.
Affected
Teams running AI coding agents on public repositories in default configurations (CVE-2026-12537, CVE-2026-54316); an unprivileged GitHub issue or pull request can reach CI runners and expose workflow secrets and tokens.
Fix
Patch the agents, restrict their tools with allowlists rather than blocklists, give triage and review agents read-only tokens, and keep separate agent runs from sharing writable directories.

Google removes AI agent workflows after a GitHub issue could hijack a privileged agent

Pillar Security showed that Google's Agent Development Kit repository could be turned against itself through a poisoned pull request or issue. The public repository ran a low-privileged triage agent that responded to outside contributions, and a higher-privileged agent reserved for maintainers. Because the triage agent posted through a bot account that counted as a repository collaborator, a prompt injection could make it post a command that satisfied the privileged workflow's trust check, invoking the maintainer-level agent. That crossed into a job holding a long-lived access token, a Google API key, and a cloud service-account credential, enabling code execution on the runner and secret theft. Google deleted the affected workflows.

Check
Review any AI agent workflows that act on untrusted pull requests or issues, and check whether a low-privileged agent can trigger a higher-privileged one through a shared bot identity.
Affected
Teams running tiered AI agent workflows in code repositories; untrusted issue or pull-request content can prompt-inject a public agent into invoking a privileged one, exposing continuous integration secrets and code execution.
Fix
Give agents scoped, non-collaborator identities, keep untrusted content from reaching privileged workflows, require human approval for sensitive agent actions, and minimize the tokens and credentials an agent job can access.

Critical TeamCity flaw lets unauthenticated attackers run commands on the CI server

JetBrains patched a critical flaw in TeamCity, its continuous integration and delivery server, that lets an unauthenticated attacker run operating-system commands. Tracked as CVE-2026-63077 and scored 9.8, the deserialization bug affects all on-premises versions and is reached through the agent polling protocol, letting an attacker with HTTP access bypass authentication and execute commands with the privileges of the server process. JetBrains warns that exploitation exposes stored credentials and can compromise the integrity of the build pipeline. It is fixed in versions 2025.11.7 and 2026.1.3, with a patch plugin for older releases, and TeamCity Cloud is already updated. No exploitation has been reported.

Check
Upgrade on-premises TeamCity to 2025.11.7 or 2026.1.3, or apply the security patch plugin if you cannot upgrade, and restrict network access to the server.
Affected
Organizations running any on-premises TeamCity version (CVE-2026-63077); an unauthenticated attacker with HTTP access can execute commands as the server process, steal stored credentials, and tamper with build pipelines.
Fix
Patch or apply the plugin, keep TeamCity off the public internet or behind a VPN, rotate credentials the server held, and review build configurations and logs for unauthorized changes.

AsyncAPI npm packages backdoored through a hijacked build pipeline

Attackers backdoored several widely used @asyncapi npm packages, together drawing around three million weekly downloads, by hijacking the project's GitHub Actions build pipeline rather than stealing a maintainer's npm token. Because the project's own release workflow published the malicious versions, they carried valid provenance signatures, which prove where a package came from but not that the code was trustworthy. The payload was hidden in normal runtime files behind trailing whitespace and ran when the module was imported, not on install, so defenses aimed at install scripts missed it. Once loaded, it fetched an encrypted second stage, stole credentials and cloud and registry tokens, and planted persistence, even in developer tool configuration files.

Check
Check whether your projects or CI pulled the affected @asyncapi versions, focusing on systems that imported the modules, not only installed them, and review developer and build environments for stolen tokens.
Affected
Developers and CI pipelines that imported the compromised @asyncapi versions; the malware steals credentials, cloud keys, and npm and GitHub tokens and adds persistence, and valid provenance signatures made them look trustworthy.
Fix
Downgrade to the clean @asyncapi versions, remove the bad ones from lockfiles, caches, and mirrors, rotate credentials reachable from affected machines from a clean system, and harden CI against untrusted pull-request triggers.

Compromised jscrambler npm releases dropped a cross-platform infostealer on install

Attackers used a stolen publishing credential to push malicious versions of the jscrambler npm package that install a Rust infostealer as soon as the package is added to a project. Socket ties five bad versions to the same actor, published over about three hours; the malware ships as native binaries for Windows, macOS, and Linux and sweeps developer machines for cloud credentials, crypto wallets, and password-manager vaults. Because jscrambler is a build-time tool used in development and CI, the stealer runs where deploy tokens, cloud keys, and source code live. Partway through, the dropper moved into the package's main code, so installing with scripts disabled does not stop it.

Check
Check lockfiles, package logs, and CI records for the malicious jscrambler versions installed since July 11, move to a clean release or pin to 8.13.0, and clear affected versions from caches.
Affected
Developers and CI pipelines that installed the malicious jscrambler versions; the infostealer captures AWS, Azure, and Google Cloud credentials, crypto wallets and seed phrases, and password-manager vaults from the build environment.
Fix
Remove the bad versions, rotate every credential exposed in affected developer and CI environments, hunt for temp-directory binaries and hidden persistence, and pin and verify dependencies rather than trusting a maintainer account.

FBI warns TeamPCP poisons trusted developer tools to steal cloud credentials

The FBI has issued an alert about TeamPCP, a criminal group that compromises the developer and security tools organizations trust inside their build pipelines to steal cloud credentials at scale. Rather than targeting end users, TeamPCP injects malicious code into legitimate software such as the Trivy and KICS scanners and the LiteLLM library, then pushes trojanized updates that continuous integration systems pull in automatically. Its malware harvests AWS, Google Cloud, and Azure tokens, Kubernetes service-account credentials, and more. One technique the FBI highlights is taking over npm maintainer accounts by re-registering the maintainer's long-expired recovery email domain, then using password reset to publish malicious package versions.

Check
Check whether your build pipelines pulled trojanized versions of tools like Trivy, KICS, or LiteLLM, review the FBI's indicators, and audit whether any package maintainer accounts use expired recovery email domains.
Affected
Organizations whose CI/CD pipelines automatically pull developer and security tools, and maintainers whose npm recovery email domains have lapsed; TeamPCP uses these paths to steal cloud, Kubernetes, and registry credentials.
Fix
Pin GitHub Actions to commit hashes, rotate CI/CD secrets and cloud credentials, scope publishing tokens and enforce least privilege, require phishing-resistant MFA on publishing accounts, and delay installing brand-new package versions.