Xygeni disclosed suspicious activity affecting the repository used to publish its xygeni/xygeni-action GitHub Action, where an unidentified threat actor attempted to introduce a compact command-and-control (C2) implant. While malicious code was reportedly blocked from being merged into the main branch via branch protection/detection rules, the actor pivoted to tag poisoning by moving the mutable v5 tag to point to a malicious commit created during the pull-request attempts. As a result, any CI/CD workflows pinned to xygeni/xygeni-action@v5 could have pulled the compromised code without any visible change to workflow definitions; Xygeni removed the tag as part of incident response after community reports helped surface the issue.
Xygeni attributed initial access to compromised credentials tied to a maintainer token and a GitHub App installed on the repository, and stated it found no evidence that its broader platform or customer data was compromised. Wiz also tracked the incident as an action repository hijack, reinforcing the supply-chain risk of mutable tags in GitHub Actions and the need to pin actions to immutable commit SHAs or tightly controlled release tags.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
On March 11, 2026, Xygeni publicly stated that the incident was caused by compromise of a GitHub App private key with excessive permissions, used with a maintainer personal access token to create and approve pull requests. The company said it found no evidence of compromise to its platform or customer data, and announced mitigations including release immutability, tighter permissions, mandatory signed commits, reduced write access, and guidance for customers to pin safe SHAs, audit CI logs, and rotate secrets.
By March 10, 2026, community reports and StepSecurity analysis had identified that the Xygeni GitHub Action v5 tag was serving a malicious commit. Their findings helped establish the likely exposure window and the risk to CI environments.
Xygeni said it identified follow-on malicious activity on March 9, 2026, during the repository compromise. The company responded by removing the affected tag as part of incident containment.
Between March 3 and March 10, 2026, users running xygeni/xygeni-action@v5 may have executed a reverse-shell C2 implant on CI runners, potentially exposing GITHUB_TOKEN values, repository secrets, and source code. The compromise stemmed from tag poisoning rather than malicious code merged into the main branch.
An unidentified attacker compromised Xygeni’s official GitHub Action repository by poisoning the mutable v5 tag so workflows using xygeni/xygeni-action@v5 would resolve to a malicious commit. Reports indicate the malicious tag exposure lasted for up to seven days, beginning on March 3, 2026.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.