Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Summary

Cybersecurity researchers have uncovered a credential-stealing campaign that compromised two prominent open-source maintainer accounts. The attackers injected a malicious GitHub Actions workflow into over 340 repositories, including those associated with the author of the pyxel game engine.

IFF Assessment

FOE

This campaign is bad news for defenders as it demonstrates a successful method for attackers to compromise open-source projects and steal credentials.

Defender Context

This incident highlights the risks associated with compromised open-source maintainer accounts and the potential for malicious code to be injected into widely used projects. Defenders should be vigilant about reviewing the integrity of dependencies and CI/CD pipelines, especially for open-source software.

Read Full Story →