{"id":245167,"date":"2026-10-10T09:18:00","date_gmt":"2026-10-10T14:18:00","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/10\/credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-repositories"},"modified":"2026-10-10T09:18:00","modified_gmt":"2026-10-10T14:18:00","slug":"credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-repositories","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/10\/credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-repositories","title":{"rendered":"Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-repositories.webp\"><\/a><\/p>\n<p>Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.<\/p>\n<p>\u201cUsing the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,\u201d StepSecurity <a href=\"https:\/\/www.stepsecurity.io\/blog\/ghostaction-returns\" target=\"_blank\" rel=\"noopener\">said<\/a>. \u201cEight hours later, the account of Henry Wu (henrywoo), the original author of Uber\u2019s athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window, 21:10\u201321:26 UTC.\u201d<\/p>\n<p>As of October 9, 2026, Socket <a href=\"https:\/\/socket.dev\/blog\/ghostaction-cloud-credentials\" target=\"_blank\" rel=\"noopener\">said<\/a> it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. \u201cUsing the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,\u201d StepSecurity said. [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-245167","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/245167","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=245167"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/245167\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=245167"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=245167"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=245167"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}