{ads}

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories



October 10, 2026 at 12:44AM

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

from The Hacker News https://ift.tt/Dw0C7Tk

0 Response to "Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories"

Post a Comment

Article Top Ads

Central Ads Article 1

Middle Ads Article 2

Article Bottom Ads