One Supply Chain Attack to Rule Them All – Poisoning GitHub’s Runner Images

I successfully exploited a critical misconfiguration vulnerability in GitHub’s actions/runner images repository. I gained control over build agents used by the repository, accessed secrets, a…