CI/CD Compromise 2025 Incident #50 CVE-2025-30066

GhostAction campaign

Estimated Financial Impact
3325 secrets exfiltrated
Blast Radius
327 GitHub users; 817 repositories

What Happened

327 GitHub users were compromised across 817 repositories via malicious GitHub Actions workflows that exfiltrated 3,325 secrets including PyPI, npm, and DockerHub tokens. The stolen tokens were then used to attempt publishing malicious packages downstream.

○

Risk Guard: Partial

PACKAGE_ACTIVE_MALWARE on published packages; workflow-level compromise harder to detect

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARE

How Every Tool Performed

0 Caught 1 Partial 5 Missed
Tool Verdict Details
OSS Risk Guard Partial PACKAGE_ACTIVE_MALWARE on published packages; workflow-level compromise harder to detect
Socket Missed GitHub Actions workflow compromise outside package scope
Snyk Missed No workflow analysis
Sonatype (Nexus) Missed No workflow analysis
Black Duck Missed No workflow analysis
Endor Labs Missed No workflow analysis
← Ultralytics YOLO eslint-config-prettier →