A new software supply chain attack targets the popular GitHub Actions workflow actions-cool/issues-helper, executing malicious code that collects sensitive credentials and exports them to a server controlled by attackers. The attack is part of a broader trend targeting CI/CD systems by compromising widely used actions, demonstrating the deep vulnerability of modern automated software development systems.

According to researcher Varun Sharma of StepSecurity, every existing tag in the repository has been moved to point to a rogue commit that does not appear in the action's regular commit history. This commit contains malicious code that extracts credentials from CI/CD pipelines that execute the action.
See also: Google attributes Axios Supply Chain Attack to UNC1069
The “imposter commit” technique refers to a supply chain attack strategy where malicious code is injected into a project by referencing a commit or tag that only exists on a fork controlled by the adversary. This method allows attackers to bypass standard Pull Request (PR) and achieve arbitrary code execution without leaving a trace in the main repository.
The malicious commit, the cybersecurity firm says, contains code that, when executed inside a GitHub Actions runner, performs a series of actions. It first downloads the Bun JavaScript runtime to the runner, a modern alternative to Node.js that offers fast execution and a smaller footprint. It then reads memory from the Runner.Worker to extract credentials stored in environment variables or temporary files, and finally makes an outbound HTTPS call to the domain controlled by the attackers (tm-kosche[.]com) to transmit the stolen data in an encrypted manner.
See also: DAEMON Tools Supply Chain Attack: Government organizations targeted

Expansion of the attack to a second GitHub Actions repository
StepSecurity announced that 15 tags related to a second GitHub action, “actions-cool/maintain-one-comment“, have also been compromised in the same way. This indicates that the attack was broader in scope and not limited to a single repository, but was part of a coordinated campaign targeting multiple actions from the same maintainer or organization.
GitHub has since disabled access to the repository due to “violation of GitHub’s terms of service,” an action typically taken when malicious activity or a security breach is detected .
Interestingly, the “tm-kosche[.]com” export domain has been observed in the latest wave of the Mini Sha-Hulud, targeting npm packages from the @antv, suggesting that the two activities could be related or belong to the same group of attackers. This connection suggests a more organized and coordinated effort by the attackers to target multiple software ecosystems simultaneously, using common infrastructure and techniques to maximize their impact.
See also: Axios Supply Chain Attack: Malicious versions distribute RAT

Practical protection and coping tips
Organizations should treat this as a credential breach event. Immediate actions include rotating all secrets accessible to workflows using actions-cool/issues-helper, revoking and reissuing cloud access keys, GitHub PATs, npm/PyPI/NuGet tokens, Docker registry credentials, and other sensitive credentials that may have been exposed. Additionally, organizations should review CI/CD logs for any exposed secrets and review cloud audit logs for suspicious usage.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
