GitHub Token Access Via GH CLI

Rule Info

Name
GitHub Token Access Via GH CLI
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the GitHub CLI (gh) being used to retrieve stored authentication tokens. Malicious packages and scripts have been observed using these commands to silently exfiltrate the victim's stored GitHub authentication token.
Date
2026-06-08 00:00:00
Modified
None
Id
9d1e3a7c-5f2b-4d8e-a0c4-6b3f9e2d1a7b
Tags
attack.credential-access attack.t1528
Type
Nextron Sigma feed only (private)

Rule History