THREAT OPS › Threat News › CI/CD pipeline abuse: the problem no one is watching
CI/CD pipeline abuse: the problem no one is watching
<h2 id="preamble">Preamble</h2> <p>In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out
Attributed threat actors
- Contagious InterviewG1052
MITRE ATT&CK techniques
- Code SigningT1553.002
- Supply Chain CompromiseT1195
- Unsecured CredentialsT1552
- TimestompT1070.006
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- Account ManipulationT1098
- Valid AccountsT1078
- CredentialsT1589.001
- Compromise Software Supply ChainT1195.002
- Valid AccountsAML.T0012
- Command and Scripting InterpreterAML.T0050
- Unsecured CredentialsAML.T0055
Indicators of compromise
- CVE-2025-30066cve
- https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolenurl
- https://orca.security/resources/blog/pull-request-nightmare-github-actions-rce/url
- https://about.codecov.io/apr-2021-post-mortem/url
- https://orca.security/resources/blog/hackerbot-claw-github-actions-attack/url
- https://www.reversinglabs.com/blog/shai-hulud-worm-npmurl
- https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitationurl
- https://kl4r10n.tech/blog/when-git-history-liesurl
- https://docs.anthropic.com/en/docs/claude-codeurl
- https://www.legitsecurity.com/blog/github-privilege-escalation-vulnerability-0url
- https://www.abstract.security/blog/contagious-interview-tracking-the-vs-code-tasks-infection-vectorurl
- http://ela.st/slackurl
- https://discuss.elastic.co/c/security/endpoint-security/80url
- https://www.synacktiv.com/en/publications/github-actions-exploitation-dependaboturl
- static-www.elastic.codomain