Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.

“Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

The Fastest Path to AI Adoption Runs Through Security

The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance

Born Against, or why hobby programming communities are against LLM usage

Born Against, or why hobby programming communities are against LLM usage Source: Hacker News

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all