Why This Report Matters

Key Insights
This attack didn’t require sophisticated tooling—just a pull request.
- A “pwn request” vulnerability enabled arbitrary code execution in the CI pipeline
- No privileges required—any GitHub user could trigger the exploit
- Secrets, including GitHub tokens and third-party credentials, were immediately exposed
- The compromised token enabled direct code changes, workflow manipulation, and release tampering

What You'll Learn
Understand how a routine workflow becomes a supply chain attack—and how to stop it.
- How pull_request_target turns CI pipelines into attack surfaces
- The exact mechanics of a “pwn request” exploit
- How attackers move from untrusted code to trusted execution
- What secrets are exposed—and how they’re weaponized
- The fastest path to containment, hardening, and prevention






