Credential-Stealing GitHub Actions Workflows Discovered in Tens of Thousands of Repositories
Campaign leverages compromised maintainer accounts to inject malicious workflows, potentially exfiltrating secrets and tokens.

Key Takeaways
- Threat actors compromised two high-profile open-source maintainer accounts to inject malicious GitHub Actions workflows.
- Over 340 repositories were affected, including projects maintained by Takashi Kitao (pyxel) and another unnamed maintainer.
- The malicious workflows are designed to capture credentials and secrets during execution.
Related Security News

AhsayCBS Vulnerabilities Exploited to Deploy XMRig Miners
Threat actors are exploiting two recently disclosed vulnerabilities in the AhsayCBS backup utility to gain unauthorized access, deploy web shells, and install XMRig cryptocurrency miners. The attacks involve flaws that permit improper authentication and other weaknesses to seize control of affected devices globally.




