A sophisticated supply chain attack has compromised the popular actions-cool/issues-helper GitHub Action, redirecting all existing tags to imposter commits designed to steal CI/CD credentials. The attack represents a new evolution in software supply chain exploitation, bypassing traditional code review processes entirely.
The Imposter Commit Technique
Unlike traditional supply chain attacks that inject malicious code through pull requests or direct commits, this attack used “imposter commits”—deceptive references that point to malicious code existing only in an adversary-controlled fork, rather than the original trusted repository.
StepSecurity researcher Varun Sharma explained: “Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action’s normal commit history. That commit contains malicious code that exfiltrates credentials from CI/CD pipelines that run the action.”
How the Attack Worked
When a GitHub Actions workflow referenced the compromised action by version tag, the following sequence occurred:
- The workflow pulled the malicious commit (thinking it was legitimate)
- The action downloaded the Bun JavaScript runtime to the runner
- It read memory from the Runner.Worker process to extract credentials
- Stolen data was exfiltrated via HTTPS to
t.m-kosche[.]com
Connection to Mini Shai-Hulud Campaign
The exfiltration domain overlaps with the Mini Shai-Hulud campaign that recently compromised @antv npm packages, suggesting both attacks are part of a coordinated operation. Philipp Burckhardt, head of threat intelligence at Socket, confirmed: “That points to the same Mini Shai-Hulud activity cluster, not a separate npm-only incident.”
Scope of Compromise
In addition to issues-helper, 15 tags associated with actions-cool/maintain-one-comment were also compromised with identical functionality. GitHub has since disabled access to both repositories due to violations of its terms of service.
StepSecurity warned: “Because every tag now resolves to malicious commits, any workflow that references the action by version pulls the malicious code on its next run. Only workflows pinned to a known-good full commit SHA are unaffected.”
Remediation
Organizations using these actions must:
- Immediately remove references to
actions-cool/issues-helperandactions-cool/maintain-one-comment - Rotate all CI/CD credentials that may have been exposed
- Pin future actions to full commit SHAs instead of version tags
- Monitor outbound connections from CI/CD runners for suspicious domains
Reflection
The imposter commit technique demonstrates a fundamental weakness in how GitHub Actions resolves dependencies. Tags are mutable references that can be rewritten by anyone with write access to a repository—whether that access was obtained legitimately or through compromise.
For enterprises relying on GitHub Actions for CI/CD, the lesson is unequivocal: never trust tags. Pinning to full commit SHAs provides cryptographic assurance that the code you’re running is exactly what you reviewed. Anything less is an invitation to supply chain compromise.