ThreatCluster

Shai Hulud v2 Targets GitHub Actions to Exfiltrate Secrets

First seen 27 Nov 2025, 17:34 UTC GbhackersCybersecuritynewsReddit 26

Article Content

Browse articles
ThreatCluster

The Shai Hulud v2 malware exploits GitHub Actions workflows to steal sensitive information from repositories. This attack vector affects developers and organizations using GitHub, potentially compromising their source code and secrets. The vulnerability allows unauthorized access to secrets stored in GitHub Actions, raising significant security concerns.