The Hacker News

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

By The Hacker News

1 min read
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
AI-generated illustration

Got news to share with the events industry?

Submit a press release or story tip and reach thousands of event professionals.

Get in touch→

More in Cybersecurity, Cryptography & Digital Trust

Related Insights