Shai Hulud v2 Targets GitHub Actions to Exfiltrate Secrets
First seen 27 Nov 2025, 17:34 UTC
•

•26
Export
Article Content
Browse articles
The Shai Hulud v2 malware exploits GitHub Actions workflows to steal sensitive information from repositories. This attack vector affects developers and organizations using GitHub, potentially compromising their source code and secrets. The vulnerability allows unauthorized access to secrets stored in GitHub Actions, raising significant security concerns.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
Amazon Q Developer Vulnerability Enables Cloud Credential Theft
LiteLLM Supply Chain Attack Exposes Critical Credentials
Bitwarden CLI Compromised in Supply Chain Attack via npm
Iranian Hackers Breach US Gas Station Fuel Monitoring Systems