Credential-Stealing GitHub Actions Workflows Hit 340+ Repositories
Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts to push a malicious GitHub Actions workflow into over 340 repositories. The attack began with the account of Takashi Kitao, author of the 18,400-star game engine pyxel, spreading the workflow to 27 repositories starting at 13:20 UTC.
- Malicious workflow pushed to more than 340 repositories
- Two high-profile open-source maintainer accounts compromised
- 27 repositories hit via pyxel author's account from 13:20 UTC
- Campaign targets credential theft through GitHub Actions
Read next
Security