Xygeni GitHub Action Compromised Via Tag Poison
Attackers compromised the Xygeni GitHub Action repository through tag poisoning, maintaining an active command and control implant for up to a week. The attack targeted the xygeni/xygeni-action package, a supply chain component used by developers for application security scanning. This incident demonstrates a critical risk in GitHub-based dependency distribution where malicious versions can reach dependent projects.
Summary
Attackers compromised the Xygeni GitHub Action repository through tag poisoning, maintaining an active command and control implant for up to a week. The attack targeted the xygeni/xygeni-action package, a supply chain component used by developers for application security scanning. This incident demonstrates a critical risk in GitHub-based dependency distribution where malicious versions can reach dependent projects.
Indicators of Compromise
- malware — xygeni/xygeni-action C2 implant
- malware — tag poison attack