Researchers expose credential‑theft campaign that injected malicious GitHub Actions into hundreds of repositories
Cybersecurity analysts have revealed a coordinated effort to steal credentials by compromising two high‑profile open‑source maintainer accounts and using them to push malicious GitHub Actions workflows into more than 340 repositories.
The operation leveraged the account of Takashi Kitao, a well‑known maintainer whose project has amassed over 18,000 stars on GitHub, to introduce a workflow file that executes on every code push and silently harvests authentication tokens.
While the malicious workflow was directly observed in roughly three hundred and forty distinct repositories, its design allows it to propagate through forks and downstream projects, potentially affecting tens of thousands of codebases that rely on the same automation scripts.
The injected workflow contains steps that capture environment variables, including personal access tokens and SSH keys, and transmit them to an external server controlled by the attackers, giving them unfettered access to the compromised accounts.
GitHub was alerted to the intrusion, promptly revoked the exposed credentials and removed the offending workflow files. Researchers advise repository owners to audit recent commits, rotate all secrets, and enable GitHub's built‑in token‑scanning features.
This incident adds to a growing list of supply‑chain attacks that target continuous integration and delivery pipelines, a vector that has been exploited in high‑profile breaches such as the SolarWinds compromise. The ease with which automation scripts can run with elevated privileges makes them attractive targets for threat actors.
Security experts recommend adopting a least‑privilege approach for automation tokens, enforcing required status checks before merges, and regularly reviewing permission scopes. Ongoing monitoring for similar workflow patterns is expected as defenders work to contain the broader impact of the campaign.
Comments (0)
Be the first to comment.
Join the discussion