GitHub Action - Tool

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 24, 2026
Last Seen
May 19, 2026

GitHub Action is a tool tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 24, 2026; most recent activity May 19, 2026.

Related Threat Clusters

  • Bitwarden CLI Compromised in Supply Chain Attack via npm

    A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…

    18 articles · Updated April 24, 2026
  • Critical RCE Vulnerability in Google Gemini CLI Exposes CI/CD Pipelines

    Google has issued urgent security updates for its Gemini CLI and GitHub Action to address a critical vulnerability, identified as GHSA-wpqr-6v78-jr5g. This flaw allows for Remote Code Execution (RCE) attacks due to…

    14 articles · Updated April 27, 2026
  • Supply Chain Attack on GitHub Action Exposes CI/CD Credentials

    A supply chain attack has compromised the GitHub Action 'actions-cool/issues-helper', exposing sensitive CI/CD secrets. The attacker manipulated Git tags, redirecting them to an imposter commit (1c9e803) without…

    3 articles · Updated May 19, 2026

Recent Intelligence Reports

  • Compromised GitHub Action Exfiltrates Workflow Credentials to Attacker Domain — Cybersecuritynews · May 19, 2026
  • Critical Gemini CLI Flaw Raises Supply Chain Security Concerns — Gbhackers · April 27, 2026
  • Checkmarx supply chain attack impacts Bitwarden npm distribution path — Securityaffairs.Co · April 24, 2026

CVSS v3.1 Breakdown