{"success":true,"data":{"id":"cloud-build-step-injection","label":"Spoofed CI-notification claiming a new privileged build step has been \"injected\" into the repo's .github/workflows/ or GCB pipeline yaml. \"Approve the injected step\" CTA causes the developer to merge a malicious workflow job that exfiltrates GITHUB_TOKEN / cloud credentials. Real GitHub Actions / GCB pipeline-change notifications arrive from canonical CI senders — never from unknown domains demanding out-of-band approval for an \"injected\" build step. Sender NOT on the CI-publisher canonical allowlist (github.com, circleci.com, google.com, etc.). Source: Red-Team R8 multi-agent council C4 (supply-chain specialist).","description":"Spoofed CI-notification claiming a new privileged build step has been \"injected\" into the repo's .github/workflows/ or GCB pipeline yaml. The \"Approve the injected step\" CTA causes the developer to merge a malicious workflow job that exfiltrates GITHUB_TOKEN or cloud credentials. Real GitHub Actions / GCB pipeline-change notifications arrive from canonical CI senders (github.com, google.com, circleci.com) — never from unknown domains demanding out-of-band approval for an \"injected\" build step. Supply-chain attack vector: merged malicious workflow step → GITHUB_TOKEN / cloud creds exfiltrated via CI environment. Sender NOT on the CI-publisher canonical allowlist. Source: Red-Team R8 multi-agent council C4 (supply-chain specialist).","tier":"warning","category":"other","isThin":false}}