GitHub Actions Credential Theft Campaign Compromises Open-Source Repos
Attackers hijacked popular open-source maintainer accounts to inject malicious workflows into hundreds of repositories. The campaign highlights risks in CI/CD pipelines and third-party code dependencies.
TL;DR
- Cybercriminals used compromised maintainer accounts to push credential-stealing GitHub Actions workflows.
- Over 340 repositories were affected, including ones from high-profile open-source projects.
- The attack leveraged trusted identities to bypass security controls and spread malicious code.
- Organizations are urged to audit GitHub Actions permissions and monitor for suspicious workflow changes.
- Supply chain risks in CI/CD environments remain a critical concern for software security teams.
A widespread credential theft operation has been uncovered targeting GitHub repositories through maliciously injected Actions workflows. Attackers gained access to prominent open-source maintainer accounts and used them to distribute automation scripts designed to exfiltrate secrets and tokens.
Security researchers identified that the campaign leveraged social engineering and account takeovers to gain initial access. Once inside, attackers modified existing workflows or added new ones that would silently capture repository secrets during routine operations. This method exploits the trust placed in established maintainers and automated systems.
Attack Vector and Impact
- Attackers compromised at least two high-profile open-source maintainer accounts to distribute malicious workflows.
- One compromised account belonged to Takashi Kitao, creator of the 18,400-star Pyxel game engine.
- In total, over 340 repositories received unauthorized workflow modifications between October 12-13, 2026.
- The malicious workflows were designed to steal GitHub secrets, deploy keys, and other sensitive credentials.
- Repositories using default or overly permissive Actions permissions were particularly vulnerable.
Defensive Recommendations
- Audit all GitHub Actions workflows for unexpected changes, especially those involving external domains or data exfiltration patterns.
- Restrict Actions permissions using 'permissions' block in workflow files to limit scope of potential compromise.
- Enable branch protection rules requiring reviews for workflow changes in public repositories.
- Monitor GitHub audit logs for unusual activity such as new workflow executions or secret access events.
- Implement multi-factor authentication and use dedicated machine accounts for automated deployment processes.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.