maennchen

maennchen

OpenSSF Siren published a TLP:CLEAR advisory (March 1, 2026) about an ongoing attack campaign called “hackerbot-claw”. This is being exploited in the wild right now.

Advisory:

What they’re doing

Attackers are scanning public repositories for weak GitHub Actions setups and chaining together common CI mistakes, for example:

  • Misusing pull_request_target
  • Checking out and running fork code in privileged workflows
  • Modifying scripts in PRs that later get executed by CI
  • Injecting shell via untrusted expressions like ${{ github.event.pull_request.title }}
  • Sneaking commands through branch names or file paths

A simple but dangerous example:

run: echo "${{ github.event.pull_request.title }}" | sh

If you interpolate untrusted ${{ }} values directly into run: steps, you’re effectively handing the shell attacker-controlled input.

The underlying issues are not new. The security community has warned about these patterns for years. What’s different now is automation. This campaign appears to use AI to scan and exploit repositories at scale. Weak configurations don’t stay unnoticed anymore.

What I’d recommend

  • Avoid pull_request_target unless you really need it
  • Never run untrusted fork code in privileged workflows
  • Don’t expand untrusted ${{ }} expressions directly in shell commands
  • Explicitly restrict GITHUB_TOKEN permissions (default to contents: read)
  • Require review for changes under .github/workflows/*
  • Pin third-party actions by commit SHA
  • Rotate secrets if you’re unsure what may have run

It’s also worth adding automated checks:

We recently enabled zizmor in Elixir:
https://github.com/elixir-lang/elixir/pull/15114

If you maintain BEAM projects, it’s a good moment to re-check your workflows.

Where Next? Top

Trending in News & Updates Top

sorenone
Today we’re releasing Oban for Python. Not an Oban client in Python. Not a pythonx wrapper embedded in Elixir. Nope, it’s a fully operati...
New
bartblast
I’ll be using this thread to share Hologram patch release announcements. Minor releases will continue to get dedicated threads with blog ...
New
sorenone
This release unifies configuration for queues, repos, and services, swaps opaque timing integers for readable durations, and backports pe...
New
pcharbon
:heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::heart::hea...
New
nature
NatureWhistle v0.4.1 is out! :tada: This release is a pretty significant step forward for the project. When I first built NatureWhistle,...
New
webofbits
Aludel 0.7.0 is released :tada: Since 0.5.0, Aludel has grown into a much more complete LLM evaluation toolkit for Elixir and Phoenix app...
New

Other Trending Topics Top

mudasobwa
I am happy to introduce the very α version of the new programming language compiled to BEAM. Welcome Cure. It has literally three kille...
New
marciok
Hi there! We created Gust: A task orchestrator inspired by Airflow. For those who have never heard about Aiflow, it’s a Python-based wor...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Dmk
Xamal is a deployment tool for Elixir apps that deploys native releases to bare metal servers over SSH. It’s a port of GitHub - basecamp/...
New
netoum
Corex is an accessible, unstyled UI component library for Phoenix that integrates Zag.js state machines using Vanilla JavaScript and Live...
New
webofbits
With AI doing more of the implementation work, I’ve been wondering how much coding I should deliberately keep doing myself. My main conc...
#ai
New

We're in Beta

About us Mission Statement

Options

Thread Display Mode




Thread Preview

Skip Thread Previews