
AI Autofix Supply Chain Attack: The Snowflake Jira GitHub Actions Injection, Explained
The AI autofix supply chain attack that reached Snowflake’s internal Jira did not require a poisoned dependency, a malicious model, or an AI-authored backdoor. It required two ordinary lines of GitHub Actions YAML: an issue title interpolated into a shell run: block, and an if: guard that evaluated to true for every user on the internet. What Actually Happened at Snowflake: June 18 to June 23, 2026 On 2026-06-18, pull request #1218 merged into snowflakedb/snowflake-connector-net. Its title reads as routine maintenance: “SNOW-2069227 : Update jira workflows”. The merge commit is 4a1b8ce, and the diff touches two files for +98/-128 lines across four commits. One of those files, .github/workflows/jira_issue.yml, became a remote code execution primitive for anyone with a GitHub account. ...