By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code
Tech News

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code

By Viral Trending Content 4 Min Read
Share
SHARE

Sep 06, 2024Ravie LakshmananSoftware Security / Hacking

Threat actors have long leveraged typosquatting as a means to trick unsuspecting users into visiting malicious websites or downloading booby-trapped software and packages.

These attacks typically involve registering domains or packages with names slightly altered from their legitimate counterparts (e.g., goog1e.com vs. google.com).

Adversaries targeting open-source repositories across platforms have relied on developers making typing errors to initiate software supply chain attacks through PyPI, npm, Maven Central, NuGet, RubyGems, and Crate.

Cybersecurity

The latest findings from cloud security firm Orca show that even GitHub Actions, a continuous integration and continuous delivery (CI/CD) platform, is not immune from the threat.

“If developers make a typo in their GitHub Action that matches a typosquatter’s action, applications could be made to run malicious code without the developer even realizing,” security researcher Ofir Yakobi said in a report shared with The Hacker News.

The attack is possible because anyone can publish a GitHub Action by creating a GitHub account with a temporary email account. Given that actions run within the context of a user’s repository, a malicious action could be exploited to tamper with the source code, steal secrets, and use it to deliver malware.

All that the technique involves is for the attacker to create organizations and repositories with names that closely resemble popular or widely-used GitHub Actions.

If a user makes inadvertent spelling errors when setting up a GitHub action for their project and that misspelled version has already been created by the adversary, then the user’s workflow will run the malicious action as opposed to the intended one.

“Imagine an action that exfiltrates sensitive information or modifies code to introduce subtle bugs or backdoors, potentially affecting all future builds and deployments,” Yakobi said.

“In fact, a compromised action can even leverage your GitHub credentials to push malicious changes to other repositories within your organization, amplifying the damage across multiple projects.”

Orca said that a search on GitHub revealed as many as 198 files that invoke “action/checkout” or “actons/checkout” instead of “actions/checkout” (note the missing “s” and “i”), putting all those projects at risk.

This form of typosquatting is appealing to threat actors because it’s a low-cost, high-impact attack that could result in powerful software supply chain compromises, affecting several downstream customers all at once.

Cybersecurity

Users are advised to double-check actions and their names to ensure they are referencing the correct GitHub organization, stick to actions from trusted sources, and periodically scan their CI/CD workflows for typosquatting issues.

“This experiment highlights how easy it is for attackers to exploit typosquatting in GitHub Actions and the importance of vigilance and best practices in preventing such attacks,” Yakobi said.

“The actual problem is even more concerning because here we are only highlighting what happens in public repositories. The impact on private repositories, where the same typos could be leading to serious security breaches, remains unknown.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

All-island coordination needed to unlock tech scale-up opportunities

Samsung Reveals 2026 Micro RGB Series

Can Google Pixel 10 Pro Fold Replace Your Laptop? I Switched To Find Out

The Ultra-Realistic AI Face Swapping Platform Driving Romance Scams

Bank of Ireland warns customers to be wary of “smishing” scams this Christmas

TAGGED: Cyber Security, Cybersecurity, GitHub Actions, Internet, Malware, Open Source, software development, Software Supply Chain, typosquatting
Share This Article
Facebook Twitter Copy Link
Previous Article Venezuela's opposition leader leaves country for Spain
Next Article US Supreme Court judge says German socialite gifted him €810 tickets
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Does Greg Biffle Have Children? Meet the Former NASCAR Racer’s Kids & Family
Celebrity
Xbox Sales in US For November 2025 Hit All-Time Low, Fall by 70% Year-On-Year
Gaming News
XRP’s familiarity helps push ETFs past $1B assets: Exec
Crypto
Dyson V11 Cordless Vacuum Is 44% Off and Now Costs Nearly the Same as Older Models
Gaming News
Dogecoin And Shiba Inu Make Coinbase’s List In Latest Product Launch
Crypto
All-island coordination needed to unlock tech scale-up opportunities
Tech News
Meesho shares rally 8%, double from IPO price in just 7 sessions. What’s driving the surge?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

XRP’s familiarity helps push ETFs past $1B assets: Exec

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
XRP’s familiarity helps push ETFs past $1B assets: Exec
December 19, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?