Back to Feed
Supply ChainMar 11, 2026

Xygeni GitHub Action Compromised Via Tag Poison

Attackers compromised the Xygeni GitHub Action repository through tag poisoning, maintaining an active command and control implant for up to a week. The attack targeted the xygeni/xygeni-action package, a supply chain component used by developers for application security scanning. This incident demonstrates a critical risk in GitHub-based dependency distribution where malicious versions can reach dependent projects.

Summary

Attackers compromised the Xygeni GitHub Action repository through tag poisoning, maintaining an active command and control implant for up to a week. The attack targeted the xygeni/xygeni-action package, a supply chain component used by developers for application security scanning. This incident demonstrates a critical risk in GitHub-based dependency distribution where malicious versions can reach dependent projects.

Indicators of Compromise

  • malware — xygeni/xygeni-action C2 implant
  • malware — tag poison attack