Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

GitHub Actions

4 articles

The Cache That Bites Back: GitHub Actions Cache Poisoning Attacks

How attackers turn GitHub Actions' shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.

Updated 25 September 2026
Supply Chain GitHub Actions Red Team

Shai-Hulud One Year Later: From Stolen Tokens to Compromised CI Trust

A year of Shai-Hulud attacks shows where npm defenses stop: compromised CI jobs can abuse legitimate publishing identities. Here is where to break the chain.

19 September 2026
Supply Chain GitHub Actions Blue Team

Cordyceps and GitHub Actions: When CI/CD Trust Boundaries Become the Supply Chain Attack

Novee's Cordyceps research is a reminder that GitHub Actions workflows are executable attack surface, not harmless YAML. Here is how to audit the trust boundary before an outside pull request borrows maintainer authority.

25 June 2026
Supply Chain GitHub Actions CI/CD

Shai-Hulud: The Open-Source GitHub Actions Token Harvester That Just Went Public

TeamPCP's Shai-Hulud is a TypeScript/Bun C2 framework targeting GitHub Actions CI/CD pipelines — it steals GitHub tokens, exfiltrates via a fake git domain, and has now been open-sourced for anyone to deploy.

13 May 2026
Supply Chain Red Team Threat Intelligence
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege