chiprook
← Security
SecurityOctober 10, 2026, 02:14

Credential-Stealing GitHub Actions Workflows Hit 340+ Repositories

Researchers disclosed an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts to push a malicious GitHub Actions workflow into over 340 repositories. The attack began with the account of Takashi Kitao, author of the 18,400-star game engine pyxel, spreading the workflow to 27 repositories starting at 13:20 UTC.

Credential-Stealing GitHub Actions Workflows Hit 340+ Repositories
#GitHub#Pyxel
Read next
Security

Tensorlake npm package compromised to spread Shai-Hulud credential-stealing worm

Security

Audit of 60 public GitHub Actions workflows finds 6 exploitable via pull_request_target

Security

Shai-Hulud attack steals 170 private CrowdSec repositories

Security

MCP Python SDK flaw lets malicious servers steal OAuth credentials