Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
“Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity said. “Eight hours later, the account of Henry Wu (henrywoo), the original author of Uber’s athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window, 21:10–21:26 UTC.”
As of October 9, 2026, Socket said it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.
