Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories: A Growing Threat to Open-Source Security




A credential-stealing campaign has been identified in tens of thousands of GitHub repositories, compromising the GitHub credentials of two high-profile open-source maintainers. The attackers have been using a GhostAction supply chain attack campaign to compromise the GitHub credentials of these maintainers, and the malicious workflow has been identified in over 500 GitHub accounts. Developers are advised to check their repositories for either of the two GitHub workflows since August 31, 2026, and assume compromise, if present.

The use of credential-stealing workflows is a sophisticated technique that can be used to compromise the security of open-source projects, and it's essential that developers take steps to prevent such attacks. The development highlights the need for developers to be vigilant in protecting their codebases and to take steps to prevent such attacks.



  • Over 340 repositories were affected by a credential-stealing campaign that compromised two high-profile open-source maintainer accounts.
  • The malicious workflow was designed to exfiltrate sensitive data, including cloud, AI, and SaaS credentials, from the working tree and entire git history.
  • The compromised accounts belonged to Takashi Kitao and Henry Wu, and the malicious workflow was first detected in their repositories.
  • The workflow has been identified in over 500 GitHub accounts and affected tens of thousands of repositories since October 7, 2026.
  • Developers are advised to check their repositories for the malicious workflow and assume compromise if present.
  • The attackers used a GhostAction supply chain attack campaign to compromise GitHub credentials, resulting in the exfiltration of 3,325 secrets.



  • The open-source community has been left reeling in recent times as a sophisticated supply chain attack has been making waves across the GitHub ecosystem. Researchers have uncovered a credential-stealing campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. This development has significant implications for the security of open-source projects, and it highlights the need for developers to be vigilant in protecting their codebases.

    According to Socket, a cybersecurity firm, the malicious workflow was introduced into the GitHub repositories through the use of a compromised maintainer's GitHub credentials. The workflow, masquerading as a security audit, is designed to exfiltrate sensitive data, including cloud, AI, and SaaS credentials, from the working tree and the entire git history. The malicious workflow has been identified in over 500 GitHub accounts, and it has affected tens of thousands of repositories since October 7, 2026.

    The compromised accounts belong to Takashi Kitao, the author of the 18,400-star game engine pyxel, and Henry Wu, the original author of Uber's athenadriver. The malicious workflow was first detected in the repositories of these two high-profile maintainers, and it has since spread to other repositories across the GitHub ecosystem. The workflow has been identified in 27 repositories starting at 13:20 UTC, and it has affected 318 repositories in a 16-minute window, starting at 21:10 UTC.

    The malicious workflow is designed to run a single "Audit" step that does four things: it appends the repository's named secrets found during reconnaissance, scans the working tree for 13 credential patterns associated with AWS keys, AI services, source control services, and SaaS and cloud API keys, checks the entire git history for the same 13 patterns to harvest credentials that may have inadvertently committed to the repository and subsequently deleted, and pairs AWS access key IDs with their matching secret access keys.

    The attackers have been using a GhostAction supply chain attack campaign to compromise the GitHub credentials of these maintainers. The campaign has been attributed to GhostAction, a massive supply chain attack campaign that first came to light in September 2025. The campaign has impacted 817 repositories across 327 GitHub users, resulting in the exfiltration of 3,325 secrets, including PyPI, npm, and DockerHub tokens.

    The entire attack chain plays out as follows: the attacker obtains a maintainer's GitHub credentials, most likely a leaked personal access token (PAT) from infostealer logs or credential dumps. The repository's workflow files are scanned for secrets as part of a reconnaissance step. A workflow masquerading as a security audit is injected into the default branch under the victim's own identity. The embedded payload extracts the data and sends it to an attacker-controlled endpoint via curl.

    Developers are advised to check their repositories for either of the two GitHub workflows since August 31, 2026, and assume compromise, if present. It's recommended to revoke the compromised GitHub credential, rotate credentials, delete the malicious workflow from all branches, and check forks of the infected repositories.

    In a statement, StepSecurity said that the captured data contains the repository's named GitHub Actions secrets, including CI/CD secrets, and cloud, AI, and SaaS credentials present in the working tree and the entire git history, such as AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens.

    The entire attack chain is a significant threat to the security of open-source projects, and it highlights the need for developers to be vigilant in protecting their codebases. The use of credential-stealing workflows is a sophisticated technique that can be used to compromise the security of open-source projects, and it's essential that developers take steps to prevent such attacks.

    The attackers have already compromised 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026. The injected workflows target 2,577 secrets, including SSH private keys, Azure credentials, DockerHub and GHCR container registry credentials, database credentials, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, Telegram, Slack, and Discord bot tokens, and keys associated with Cloudflare, npm, PyPI, and AI providers.

    In at least one case observed on August 30, 2026, the threat actors altered the "kuafuai/DevOpsGPT" repository to embed an XMRig cryptocurrency miner in the project's Docker image. As of writing, no malicious package releases have been published using compromised publishing credentials.

    The development highlights the need for developers to be vigilant in protecting their codebases and to take steps to prevent such attacks. The use of credential-stealing workflows is a sophisticated technique that can be used to compromise the security of open-source projects, and it's essential that developers take steps to prevent such attacks.

    The entire attack chain is a significant threat to the security of open-source projects, and it highlights the need for developers to be vigilant in protecting their codebases. The use of credential-stealing workflows is a sophisticated technique that can be used to compromise the security of open-source projects, and it's essential that developers take steps to prevent such attacks.

    In conclusion, the credential-stealing GitHub Actions workflows that have been planted in tens of thousands of repositories are a significant threat to the security of open-source projects. The attackers have been using a GhostAction supply chain attack campaign to compromise the GitHub credentials of these maintainers, and the malicious workflow has been identified in over 500 GitHub accounts. Developers are advised to check their repositories for either of the two GitHub workflows since August 31, 2026, and assume compromise, if present. It's recommended to revoke the compromised GitHub credential, rotate credentials, delete the malicious workflow from all branches, and check forks of the infected repositories.

    The development highlights the need for developers to be vigilant in protecting their codebases and to take steps to prevent such attacks. The use of credential-stealing workflows is a sophisticated technique that can be used to compromise the security of open-source projects, and it's essential that developers take steps to prevent such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Credential-Stealing-GitHub-Actions-Workflows-Planted-in-Tens-of-Thousands-of-Repositories-A-Growing-Threat-to-Open-Source-Security-ehn.shtml

  • https://thehackernews.com/2026/10/credential-stealing-github-actions.html


  • Published: Fri Oct 9 17:06:00 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us