MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Xygeni GitHub Action compromise distributes C2 backdoor through poisoned v5 tag

Beginning on 3 March 2026, an attacker using compromised Xygeni credentials and compromised GitHub App credentials poisoned the mutable v5 tag of the official xygeni/xygeni-action repository so that it referenced a malicious commit containing a command-and-control implant. Workflows referencing xygeni/xygeni-action@v5 during the approximately 3-10 March exposure window fetched and executed the backdoored code, providing arbitrary command execution on CI runners for up to 180 seconds per workflow run. Xygeni removed the compromised tag and rotated credentials on 10 March. The incident constitutes a direct compromise of a trusted software distribution mechanism; public reporting did not establish confirmed exploitation of specific external organizations.

70

Estimated severity

70 / 100

92

Source reliability

92 / 100

Approximate Date

03/03/2026

Targeted Company

XYGENI SECURITY

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Spain

ESP

Other Affected Countries

No other affected countries reported

Target country

Spain

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Use of stolen credentialsSoftware supply chain compromiseBackdoorUnauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.