Spain
ESP
Beginning on 3 March 2026, an attacker using compromised Xygeni credentials and compromised GitHub App credentials poisoned the mutable v5 tag of the official xygeni/xygeni-action repository so that it referenced a malicious commit containing a command-and-control implant. Workflows referencing xygeni/xygeni-action@v5 during the approximately 3-10 March exposure window fetched and executed the backdoored code, providing arbitrary command execution on CI runners for up to 180 seconds per workflow run. Xygeni removed the compromised tag and rotated credentials on 10 March. The incident constitutes a direct compromise of a trusted software distribution mechanism; public reporting did not establish confirmed exploitation of specific external organizations.
Estimated severity
70 / 100
Source reliability
92 / 100
Approximate Date
03/03/2026
Targeted Company
XYGENI SECURITY
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Spain
ESP
No other affected countries reported
Target country
Spain
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone