Toggle light / dark theme

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.

“Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity said. “Eight hours later, the account of Henry Wu (henrywoo), the original author of Uber’s athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window, 21:10–21:26 UTC.”

As of October 9, 2026, Socket said it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */