INTEL_REPORT
Trail of Bits — Security engineering · published 5/22/2026, 11:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
We hardened zizmor's GitHub Actions static analyzer In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM on PyPI (see Trivy’s post-mortem for the full timeline). zizmor is a static analyzer that GitHub Actions users run to catch exactly these misconfigurations before they ship. When GitHub Actions added s…
https://blog.trailofbits.com/2026/05/22/we-hardened-zizmors-github-actions-static-analyzer
sha256:fa14b242711abcb60b0ef228af0346a2b5a770c2b2412a56d5f11bc639041db3
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.