xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning
The official Xygeni GitHub Action (xygeni-action) was compromised on March 3, 2026, via stolen maintainer credentials. An attacker injected a C2 reverse shell backdoor and moved the mutable v5 tag to the malicious commit, silently affecting all workflows referencing @v5. The v5 tag remained poisoned as of March 9, 2026.
- Disclosed
- Last updated
- Blast radius
- All repositories using @v5 tag of xygeni-action GitHub Action without pinned versions
- Ecosystems
- Attack vectors
- Affected entities
- xygeni-action · v5 (poisoned)Official GitHub Action for Xygeni supply chain security tool
The official Xygeni GitHub Action repository was compromised on March 3, 2026, through account takeover using stolen maintainer credentials. An attacker injected a full command-and-control (C2) reverse shell backdoor into the codebase and silently moved the mutable v5 tag to point to the malicious commit.
This attack leveraged GitHub's mutable tag mechanism: repositories referencing the action as @v5 in their workflow files would automatically execute the backdoored version without any visible changes to their configuration files. The attacker-controlled C2 infrastructure was hosted at 91.214.78.178, enabling reverse shell access to compromised CI/CD environments.
The v5 tag remained poisoned as of the disclosure date (March 9, 2026). Remediation requires users to immediately pin to v6.4.0 or a specific commit SHA instead of using mutable version tags. Detection and blocking of such attacks would be possible through runtime monitoring of outbound network callbacks, as demonstrated by StepSecurity's Harden-Runner.
Indicators of compromise
- Packages
- xygeni-action
- IPs
- 91.214.78.178
Remediation
- Immediately pin xygeni-action to a specific version (v6.4.0 or later) or commit SHA instead of using mutable @v5 tag
- Rotate any credentials or secrets that may have been exposed in CI/CD environments during the compromise window (March 3-9, 2026)
- Audit workflow runs between March 3-9 for unexpected outbound network connections or suspicious activity
- Implement runtime monitoring and network egress controls to detect and block unauthorized C2 callbacks in CI/CD pipelines
- Review access logs for the xygeni-action repository to identify potential credential compromise
Sources
Cite this entry
"xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed March 3, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning-xeslq4
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in gantt-for-react (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-sdk-app (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit