Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.

“Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Commercially Available Bike Generators Are Not Sustainable (2011)

Commercially Available Bike Generators Are Not Sustainable (2011) Source: Hacker News

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks

Attack Update: Top 5 Attack-IPs auf doode.info – 19.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 94.154.46.245 — 2205 requests (recent log) 89.167.35.212 — 1054 requests (recent log) 104.199.197.247 — 860 requests (recent