important · Edge — CI supply chain
Re-enabling two compromised GitHub Actions restored malicious mutable tags and re-exposed thousands of downstream repositories.
Affects
GitHub Actions, the hosted and self-hosted CI workflow system used by GitHub repositories.
Disabling the compromised repositories had interrupted downstream execution. Re-enabling them without repairing the tags restored automatic payload delivery when scheduled or event-triggered workflows ran.
Detail and 1 source
The accessible record says two actions and thousands of repositories were involved, but we do not know the repository names, tag hashes, exact count or whether executions were observed after re-enablement.
Chain to watch
A GitHub Actions repository is compromised and a commonly referenced release tag is moved to malicious code.→↓GitHub disables the compromised action, interrupting downstream execution.→↓The action is later re-enabled without removing or repairing the malicious tag.→↓A downstream repository still referencing the mutable tag starts its next scheduled or event-triggered workflow.→↓The runner downloads and executes the malicious action in its CI context.→↓The exact action repositories, affected tag hashes, downstream count and post-reenable executions are not confirmed from the available record.
Unverified chainRetrieve Socket’s full September 24 report and compare the named repositories’ tag and workflow histories before and after re-enablement.