DuckDuckGo CI/CD RCE could have backdoored every browser
Researcher 6r1ff1n found that the semver-label.yml workflow in duckduckgo/content-scope-scripts used pull_request_target with no fork checks, letting any GitHub user run code on DuckDuckGo's CI runner. Stolen secrets, including a GITHUB_TOKEN with pull-requests: write, could have pushed a poisoned unsigned release to every DuckDuckGo browser.
- Workflow ran on pull_request_target with no fork detection or approval gate
- npm install executed lifecycle scripts from the attacker's package.json
- Exposed secrets included an Anthropic API key and GITHUB_TOKEN
- Unsigned, unverified releases opened a supply-chain attack path
Read next
Security