Palo Alto Networks demonstrated how a compromised GitHub Action could become a self-propagating software supply-chain worm by traversing the GitHub Actions dependency tree. A malicious action can access workflow-runner secrets—including automatically issued GITHUB_TOKEN credentials—and use writable branches, mutable tags, or overly permissive personal access tokens to alter repositories that consume or maintain dependent actions. The researchers identified repojacking as a viable initial-access route and disclosed an example chain involving papeloto/action-zip, Veracode, and Hangfire.
The scenario highlights OWASP's CICD-SEC-05 risk of insufficient pipeline-based access controls (PBAC): CI/CD identities and workflows must receive only the permissions required for a specific job. Organizations should minimize GITHUB_TOKEN and PAT scopes, protect branches and release tags, pin third-party actions to immutable commit SHAs, restrict runner outbound network access, and review dependency relationships and secret exposure in workflows to prevent a compromised action from modifying downstream repositories.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
A closed demonstration showed a compromised rev-action propagating through rev-date-action and random-action, then leaking the VERY_SECRET secret from the-repo after an overwritten v1 tag was consumed.
Hangfire remediated its finding by deleting all workflow files that used the affected actions.
Veracode remediated its finding by replacing the vulnerable third-party action with custom Bash commands.
Researchers reported identified GitHub Actions dependency-chain issues to vulnerable projects they were able to contact, including a chain involving papeloto/action-zip, Veracode, and Hangfire.
Researchers registered the available papeloto organization name to prevent malicious exploitation of the action-zip repojacking condition.
The papeloto/action-zip repository moved to the vimtor organization while the papeloto organization namespace became available, creating a repojacking condition for consumers of the action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.