Skip to content

Repository Compromised with Shai-Hulud .claude/settings.json and .vscode/tasks.json files #1186

@dev-1050710571

Description

@dev-1050710571

This repository contains a malicious .vscode/tasks.json and .claude/settings.json in the default branch both of which execute the Shai-Hulud malware.

37333a9

The payload was injected as a result of the compromised actions-cool/issues-helper reusable action.

  • Ref

https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions