Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Categories
  3. Security
  4. CI/CD Attacks

CI/CD Attacks

The "Awesome CI/CD Attacks" project is a curated collection focused on offensive research related to continuous integration and continuous deployment (CI/CD) systems. CI/CD is a set of practices that enable development teams to deliver code changes more frequently and reliably. This list encompasses various categories, including attack vectors, case studies, tools for testing security, and methodologies for assessing vulnerabilities in CI/CD pipelines. It is particularly valuable for security researchers, DevOps professionals, and developers looking to understand potential threats and improve their systems' security posture. Users can explore this collection to gain insights into securing their CI/CD processes against malicious attacks.

ci-cdsecurity-researchdevopsvulnerabilitiesattack-vectorspenetration-testingsoftware-security
RSSView on GitHub
578 stars51 forks0 contributorsUpdated
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub

Table of Contents

7 sections · 87 projects

Publicly Exposed Sensitive Data

13 projects
(The) Postman Carries Lots of Secrets

trufflesecurity.com
All the Small Things: Azure CLI Leakage and Problematic Usage Patterns

paloaltonetworks.com
Anyone can Access Deleted and Private Repository Data on GitHub

trufflesecurity.com
Beyond S3: Exposed Resources on AWS

duo.com
CloudQuarry: Digging for secrets in public AMIs

securitycafe.ro
Employee Personal GitHub Repos Expose Internal Azure and Red Hat Secrets

aquasec.com
Fortune 500 at Risk: 250M Artifacts Exposed via Misconfigured Registries

aquasec.com
GitLab SecretsGitLab Secrets

A security tool that scans GitLab repositories for secrets in dangling or force-pushed commits.

#gitlab#devsecops#python
Stars47
Forks5
Last commit1 year ago
Hidden GitHub Commits and How to Reveal Them

neodyme.io
Holes in Your Bitbucket: Why Your CI/CD Pipeline Is Leaking Secrets

cloud.google.com
Millions of Secrets Exposed via Web Application Frontends

web.archive.org
Publicly Exposed AWS Document DB Snapshots

ramimac.me
Thousands of images on Docker Hub leak auth secrets, private keys

bleepingcomputer.com

Initial Code Execution

28 projects
ActionsTOCTOU (Time Of Check to Time Of Use)ActionsTOCTOU (Time Of Check to Time Of Use)

A proof-of-concept tool demonstrating and exploiting TOCTOU vulnerabilities in GitHub Actions approval workflows.

#toctou#actions#cicd
Stars44
Forks7
Last commit5 months ago
AWS Targeted by a Package Backfill Attack

mend.io
Can you trust ChatGPT's package recommendations?

vulcan.io
Can You Trust Your VSCode Extensions?

aquasec.com
Deep dive into Visual Studio Code extension security vulnerabilities

snyk.io
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies

medium.com
Dependency Confusions in Docker and remote pwning of your infra

errno.fr
Erosion of Trust: Unmasking Supply Chain Vulnerabilities in the Terraform Registry

boostsecurity.io
Fixing typos and breaching microsoft's perimeter

johnstawinski.com
GitHub Dataset Research Reveals Millions Potentially Vulnerable to RepoJacking

aquasec.com
Gitloker attacks abuse GitHub notifications to push malicious OAuth apps

bleepingcomputer.com
Hacking GitHub AWS integrations again

dagrz.com
How I hacked into Google's internal corporate assets

observationsinsecurity.com
How to completely own an airline in 3 easy steps

maia.crimew.gay
How We Hacked a Software Supply Chain for $50K

landh.tech
Introducing MavenGate: a supply chain attack method for Java and Android applications

blog.oversecured.com
Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests

securitylab.github.com
Keeping your GitHub Actions and workflows secure Part 2: Untrusted input

securitylab.github.com
Malicious code analysis: Abusing SAST (mis)configurations to hack CI systems

medium.com
PPE — Poisoned Pipeline Execution

medium.com
Security alert: social engineering campaign targets technology industry employees

github.blog
The Monsters in Your Build Cache – GitHub Actions Cache Poisoning

adnanthekhan.com
Thousands of npm accounts use email addresses with expired domains

therecord.media
Understanding typosquatting methods - for a secure supply chain

bytesafe.dev
Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline

legitsecurity.com
What the fork? Imposter commits in GitHub Actions and CI/CD

chainguard.dev
whoAMI: A cloud image name confusion attack

securitylabs.datadoghq.com
WordPress Plugin Confusion: How an update can get you pwned

vavkamil.cz

Post Exploitation

8 projects
From Self-Hosted GitHub Runner to Self-Hosted Backdoor

praetorian.com
Hacking Terraform State for Privilege Escalation

blog.plerion.com
Hijacking GitHub runners to compromise the organization

synacktiv.com
How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects

cycode.com
Invisible Ghost: Alarming Vulnerability in GitHub Copilot

apexhq.ai
Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory

karimrahal.com
Living off the pipelineLiving off the pipeline

A research project inventorying RCE-by-design features and code execution risks in CI/CD pipeline tools.

#supply-chain-security#code-execution#workflow-injection
Stars159
Forks14
Last commit2 months ago
The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree

paloaltonetworks.com

Defense Evasion

16 projects
#redteam tip: want to discretely extract credentials from a CI/CD pipeline?

twitter.com
Abusing Repository Webhooks to Access Internal CI/CD Systems at Scale

paloaltonetworks.com
Bypassing required reviews using GitHub Actions

medium.com
Forging signed commits on GitHub

iter.ca
GitHub comments abused to push malware via Microsoft repo URLs

bleepingcomputer.com
How a Single Vulnerability Can Bring Down the JavaScript Ecosystem

landh.tech
One Supply Chain Attack to Rule Them All – Poisoning GitHub's Runner Images

adnanthekhan.com
PR sneakingPR sneaking

Demonstrates methods for sneaking malicious code into GitHub pull requests to raise awareness of supply chain vulnerabilities.

#supply-chain-security#malware-detection#security
Stars11
Forks1
Last commit9 years ago
Remove evidence of malicious pull requests on GitHub

x.com
StarJacking – Making Your New Open Source Package Popular in a Snap

checkmarx.com
The massive bug at the heart of the npm ecosystem

blog.vlt.sh
Trojan Source

trojansource.codes
Unpinnable Actions: How Malicious Code Can Sneak into Your GitHub Actions Workflows

paloaltonetworks.com
Why npm lockfiles can be a security blindspot for injecting malicious modules

snyk.io
Working as unexpected

chainguard.dev
Zuckerpunch - Abusing Self Hosted GitHub Runners at Facebook

marcyoung.us

Tools

15 projects
ADOKitADOKit

A modular attack toolkit for Azure DevOps Services that leverages the REST API for reconnaissance, privilege escalation, and persistence.

#azure-devops#rest-api#red-teaming
Stars318
Forks35
Last commit1 year ago
GatoGato

A security tool for enumerating and exploiting pipeline vulnerabilities in GitHub Actions workflows and self-hosted runners.

#self-hosted-runners#enumeration-tool#vulnerability-scanner
Stars9
Forks1
Last commit3 months ago
Gato-XGato-X

A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.

#python-tool#cicd#red-teaming
Stars563
Forks52
Last commit3 days ago
GitHub Archive

gharchive.org
GHTorrent Project

ghtorrent-downloads.ewi.tudelft.nl
git-dumpergit-dumper

A Python tool to dump a git repository from a website, even when directory listing is disabled.

#web-security#source-code-extraction#repository-recovery
Stars2,587
Forks300
Last commit14 days ago
GitFiveGitFive

An OSINT tool to investigate GitHub profiles, tracking usernames, emails, identities, and repositories.

#multi-processing#hideandsec#json-export
Stars1,010
Forks79
Last commit9 months ago
Grep.app

grep.app
Jenkins Attack FrameworkJenkins Attack Framework

A command-line tool for security testing and offensive operations against Jenkins CI/CD servers.

#credential-dumping#jenkins#command-line-tool
Stars577
Forks60
Last commit1 year ago
Nord StreamNord Stream

A tool for extracting secrets from CI/CD environments by deploying malicious pipelines, supporting Azure DevOps, GitHub, and GitLab.

#azure-devops#cicd#azuredevops
Stars368
Forks22
Last commit13 days ago
pwn_jenkinspwn_jenkins

A collection of notes, scripts, and techniques for exploiting vulnerabilities and attacking Jenkins servers.

#credential-dumping#automation-server#pentest
Stars2,097
Forks326
Last commit2 years ago
Secrets Patterns DatabaseSecrets Patterns Database

The largest open-source database of regex patterns for detecting secrets, API keys, passwords, and tokens in code.

#secret-detection#regex-patterns#regex
Stars1,597
Forks189
Last commit11 months ago
Sourcegraph

sourcegraph.com
Token-Spray

blog.projectdiscovery.io
zizmorzizmor

A static analysis tool that finds security vulnerabilities and misconfigurations in GitHub Actions workflows.

#supply-chain-security#workflow-analysis#vulnerability-detection
Stars5,908
Forks223
Last commit10 hours ago

Related Awesome Lists

📦
Hacking

The "Awesome Hacking" project is a curated resource list designed for those interested in the field of hacking, which involves exploring and exploiting vulnerabilities in computer systems and networks. This list encompasses a wide range of categories, including penetration testing tools, ethical hacking tutorials, security research papers, and community forums. It serves as a valuable resource for beginners looking to learn the basics of cybersecurity, as well as experienced professionals seeking advanced techniques and tools. Whether you are aiming to enhance your skills or stay updated on the latest security trends, this collection offers a wealth of information to support your hacking journey.

16.1k
📦
Security

The "Awesome Security" project is a curated collection of resources focused on enhancing security practices in the digital realm. This list encompasses a wide range of categories including security tools, libraries, frameworks, tutorials, and best practices for various platforms and technologies. It is designed to benefit security professionals, developers, and system administrators alike, providing valuable insights and tools to safeguard applications and data. Whether you are a beginner looking to understand security fundamentals or an experienced practitioner seeking advanced techniques, this project offers a wealth of information to help you improve your security posture and protect your digital assets.

14.2k
📦
Malware Analysis

The "Awesome Malware Analysis" project is a curated resource list designed to assist security professionals and researchers in the field of malware analysis. Malware analysis involves examining malicious software to understand its behavior, functionality, and impact. This list includes tools for static and dynamic analysis, reverse engineering resources, malware databases, and educational materials such as tutorials and courses. It is valuable for both beginners looking to learn the basics and experienced analysts seeking advanced techniques and tools. Users can find a wealth of resources to enhance their skills and improve their malware analysis capabilities.

13.6k
📦
Web Security

The "Awesome Web Security" project is a curated collection of resources focused on the security of web applications and services. Web security encompasses practices and technologies designed to protect websites and online services from cyber threats, vulnerabilities, and attacks. This list includes tools for penetration testing, secure coding practices, frameworks, libraries, and educational materials such as articles and tutorials. It is valuable for developers, security professionals, and researchers who seek to enhance their understanding of web security and implement robust security measures. Users can find essential tools and knowledge to safeguard their web applications effectively and stay ahead of potential threats.

13.2k