B
ä»é±äž
GitHub Actionsã®ã¯ãŒã¯ãããŒãæªçšããŠèªèšŒæ å ±ãçã¿åºãå€§èŠæš¡ãªãµãã©ã€ãã§ãŒã³æ»æãGhostActionã
ð äžèšã§ãããš
GitHub Actionsã®ã¯ãŒã¯ãããŒãæªçšããŠèªèšŒæ
å ±ãçã¿åºãå€§èŠæš¡ãªãµãã©ã€ãã§ãŒã³æ»æãGhostActionãã確èªãããŸãããæ»æè
ã¯èåãªãªãŒãã³ãœãŒã¹ã¡ã³ãããŒã®ã¢ã«ãŠã³ãã䟵害ããæ°äžä»¶ã®ãªããžããªã«æªæã®ããã¯ãŒã¯ãããŒãä»èŸŒã¿ãŸãããããã«ãããPyPIãªã©ã®ã·ãŒã¯ã¬ããæ
å ±ãå«ã3,300件以äžã®èªèšŒæ
å ±ãæµåºãããšå ±åãããŠããŸãã
ð該åœå€å®
- GitHub ActionsïŒèªååæ©èœïŒãèªç€Ÿãããžã§ã¯ãã§å©çšããŠãã
- GitHubã§å ¬éãããŠãããªãŒãã³ãœãŒã¹ã©ã€ãã©ãªãèªç€Ÿéçºã«åãå ¥ããŠãã
- GitHubã®ãªããžããªã«APIããŒããã¹ã¯ãŒããªã©ã®ãSecretsããä¿åããŠãã
- pyxel ã athenadriver ãšãã£ãã©ã€ãã©ãªã瀟å ã§å©çšããŠãã
äžèšãããã«ã該åœããªã â é芳ã§OK
â
è©²åœæã®å¯Ÿå¿
GitHubãªããžããªå
ã®ã¯ãŒã¯ãããŒãã¡ã€ã« (.github/workflows/) ã«äžå¯©ãªå€æŽããªãã確èªãã䟵害ãçãããå Žåã¯çŽã¡ã«ã·ãŒã¯ã¬ããïŒAPIããŒãããŒã¯ã³çïŒãããŒããŒãããŠãã ããã
ð§ ã¡ãŒã«æ¡ãèŠã (管çè åã)
â ïž ãã㯠AI ãçæããåèäŸã§ããé
ä¿¡åã«å¿
ãå
容ãã確èªã®ããã貎瀟ã®ç¶æ³ã«åãããŠç·šéããŠãå©çšãã ãããå®éã®è¢«å®³ç¶æ³ãèªç€Ÿã®å©çšç°å¢ãèžãŸãã倿ã¯ã貎瀟ã®ã»ãã¥ãªãã£è²¬ä»»è
ã«ã確èªãã ããã
ä»¶å: ãå
±æãGitHub Actionsãæšçãšãããµãã©ã€ãã§ãŒã³æ»æïŒGhostActionïŒã«ã€ããŠ
ãç²ãããŸã§ããGitHub ActionsãæªçšããèªèšŒæ å ±çªåãã£ã³ããŒã³ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
ãGhostActionããšåŒã°ããæ»æè ããèåãªã¡ã³ãããŒã®ã¢ã«ãŠã³ãã䟵害ããæ°äžä»¶ã®ãªããžããªã«æªæã®ããGitHub Actionsã¯ãŒã¯ãããŒãæ³šå ¥ããŠã·ãŒã¯ã¬ããæ å ±ãçªåããŠããŸããããã«ãããPyPIçã®èªèšŒæ å ±ãå«ã3,300件以äžã®ã·ãŒã¯ã¬ãããæµåºãããšãããŠããŸãã
â 圱é¿ç¯å²
- GitHub Actionsãå©çšããŠãããªããžããª
- 䟵害ãããã¡ã³ãããŒã管çãããªãŒãã³ãœãŒã¹ãããžã§ã¯ããå©çšããŠããçµç¹
â å¯Ÿå¿æé
1. èªç€Ÿç®¡çãªããžããªã® `.github/workflows/` é äžã«ãæå³ããªã倿Žãäžå¯©ãªã¹ã¯ãªããã远å ãããŠããªããç£æ»ããŠãã ããã
2. å€éšã©ã€ãã©ãªã®æŽæ°å±¥æŽã確èªããäžå¯©ãªã³ãããããªãããã§ãã¯ããŠãã ããã
3. äžãäžãäžå¯©ãªã¯ãŒã¯ãããŒãæ€åºãããå Žåã¯ãçŽã¡ã«åœè©²ãªããžããªã«èšå®ãããŠããGitHub SecretsïŒAPIããŒããã¹ã¯ãŒãçïŒããã¹ãŠç¡å¹åããåçºè¡ããŠãã ããã
â åèæ å ±
- StepSecurity / Socket å ±åæž
察å¿åªå 床: é«
å¯Ÿå¿æé: éããã«
ãç²ãããŸã§ããGitHub ActionsãæªçšããèªèšŒæ å ±çªåãã£ã³ããŒã³ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
ãGhostActionããšåŒã°ããæ»æè ããèåãªã¡ã³ãããŒã®ã¢ã«ãŠã³ãã䟵害ããæ°äžä»¶ã®ãªããžããªã«æªæã®ããGitHub Actionsã¯ãŒã¯ãããŒãæ³šå ¥ããŠã·ãŒã¯ã¬ããæ å ±ãçªåããŠããŸããããã«ãããPyPIçã®èªèšŒæ å ±ãå«ã3,300件以äžã®ã·ãŒã¯ã¬ãããæµåºãããšãããŠããŸãã
â 圱é¿ç¯å²
- GitHub Actionsãå©çšããŠãããªããžããª
- 䟵害ãããã¡ã³ãããŒã管çãããªãŒãã³ãœãŒã¹ãããžã§ã¯ããå©çšããŠããçµç¹
â å¯Ÿå¿æé
1. èªç€Ÿç®¡çãªããžããªã® `.github/workflows/` é äžã«ãæå³ããªã倿Žãäžå¯©ãªã¹ã¯ãªããã远å ãããŠããªããç£æ»ããŠãã ããã
2. å€éšã©ã€ãã©ãªã®æŽæ°å±¥æŽã確èªããäžå¯©ãªã³ãããããªãããã§ãã¯ããŠãã ããã
3. äžãäžãäžå¯©ãªã¯ãŒã¯ãããŒãæ€åºãããå Žåã¯ãçŽã¡ã«åœè©²ãªããžããªã«èšå®ãããŠããGitHub SecretsïŒAPIããŒããã¹ã¯ãŒãçïŒããã¹ãŠç¡å¹åããåçºè¡ããŠãã ããã
â åèæ å ±
- StepSecurity / Socket å ±åæž
察å¿åªå 床: é«
å¯Ÿå¿æé: éããã«
Subject: [Security Alert] Supply Chain Attack via GitHub Actions (GhostAction)
Dear IT/Security Team,
We are sharing information regarding a large-scale credential-theft campaign targeting GitHub Actions workflows, attributed to 'GhostAction'.
â Overview
Attackers have compromised high-profile open-source maintainer accounts to plant malicious workflows in tens of thousands of repositories. This activity has led to the exfiltration of over 3,300 secrets, including PyPI credentials.
â Scope
- Repositories utilizing GitHub Actions
- Organizations relying on open-source projects managed by the compromised maintainers
â Action Plan
1. Audit `.github/workflows/` directories in your repositories for unauthorized changes or suspicious scripts.
2. Review commit histories of external dependencies for any anomalous activity.
3. If suspicious workflows are found, immediately rotate all GitHub Secrets (API keys, tokens, etc.) associated with the affected repositories.
â Reference
- Reports by StepSecurity and Socket
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a large-scale credential-theft campaign targeting GitHub Actions workflows, attributed to 'GhostAction'.
â Overview
Attackers have compromised high-profile open-source maintainer accounts to plant malicious workflows in tens of thousands of repositories. This activity has led to the exfiltration of over 3,300 secrets, including PyPI credentials.
â Scope
- Repositories utilizing GitHub Actions
- Organizations relying on open-source projects managed by the compromised maintainers
â Action Plan
1. Audit `.github/workflows/` directories in your repositories for unauthorized changes or suspicious scripts.
2. Review commit histories of external dependencies for any anomalous activity.
3. If suspicious workflows are found, immediately rotate all GitHub Secrets (API keys, tokens, etc.) associated with the affected repositories.
â Reference
- Reports by StepSecurity and Socket
Priority: High
Deadline: Immediate