Credential-Theft Campaign Exploits GitHub Actions Workflows in Multiple Repositories
Cybersecurity researchers uncovered a credential-theft campaign that compromised two high-profile open-source maintainer accounts to deploy malicious GitHub Actions workflows into over 340 repositories. The attack exploited the account of Takashi Kitao, creator of the 18,400-star pyxel game engine, to push malicious workflows into 27 repositories starting at 13:20 UTC.
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
*** END OF TRANSMISSION ***