Securing GitHub Actions for Node.js and Next.js: Pwn Requests, Cache Poisoning, and npm Provenance [2026]
Your CI pipeline holds the npm token, the cloud credentials, and the production deploy key, which makes it the highest-value target in the repository. This guide walks through the attack patterns that actually work against Node.js and Next.js workflows (`pull_request_target` pwn requests, script injection through `${{ }}` interpolation, cache and artifact poisoning, tag-retagging supply chain attacks such as CVE-2025-30066), then hardens them: least-privilege `GITHUB_TOKEN`, actions pinned to commit SHAs, OIDC trusted publishing instead of a long-lived `NPM_TOKEN`, protected environments, and a copy-paste hardening checklist.