LIVE · cybersecurity feed
Live wire
security

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao,…

ZeroDay News ·

Source: The Hacker News

Photo: Rrustema (CC0) via Wikimedia Commons

Cybersecurity researchers have reported an active credential-theft campaign leveraging GitHub Actions workflows, which has led to the compromise of tens of thousands of repositories. The campaign reportedly exploited two high-profile open-source maintainer accounts to propagate a malicious workflow into over 340 repositories directly. One notable instance involved the account of Takashi Kitao, the creator of the pyxel game engine, which has approximately 18,400 stars. The attacker reportedly used this account to push a malicious workflow to 27 repositories, commencing around 13:20 UTC.

The core mechanism of this attack involves the injection of a malicious GitHub Actions workflow. GitHub Actions are event-driven automation tools integrated directly into GitHub repositories, allowing developers to automate tasks like continuous integration/continuous deployment (CI/CD), code linting, and more. Workflows are defined in YAML files within the repository's .github/workflows directory. When triggered by specific events, such as a push or a pull request, these workflows execute a series of steps, which can include running scripts, building code, or interacting with external services.

In this campaign, the malicious workflow is designed to steal credentials. This typically involves steps that exfiltrate sensitive information, such as GitHub tokens, environment variables, or other secrets configured within the repository or the workflow itself. These secrets are often used to authenticate with external services or to perform privileged operations. Once exfiltrated, these credentials can be used by attackers to gain further access, modify code, or inject more malicious content into other repositories or integrated systems.

The compromise of high-profile maintainer accounts is a critical vector for this type of attack. Maintainers of popular open-source projects often have elevated privileges across numerous repositories, and their accounts are trusted by many contributors and downstream users. When such an account is compromised, attackers can leverage this trust to push malicious code or workflows into a wide array of associated repositories, leading to a significant supply chain risk. The reported scope of over 340 repositories directly affected, with the potential for tens of thousands more through transitive dependencies or forks, highlights the broad impact.

Mitigation for this class of issue typically involves several layers of defense. For users, it's crucial to review GitHub Actions workflows, especially those introduced or modified by new commits, and to scrutinize any changes originating from unexpected sources or maintainer accounts, even if seemingly legitimate. Implementing branch protection rules that require code reviews for workflow changes can help. For maintainers, strong account security practices are paramount, including the use of multi-factor authentication (MFA), regular rotation of personal access tokens (PATs), and auditing of authorized applications.

Additionally, organizations and individual developers should employ static analysis tools that can scan GitHub Actions workflows for suspicious patterns or known malicious constructs. Regularly auditing repository settings for unusual collaborators or changes to workflow permissions can also help detect compromises early. Restricting the scope of secrets and tokens used in workflows to the minimum necessary permissions and ensuring they are not over-privileged is a fundamental security practice.

This incident underscores the growing threat to the software supply chain through automated development tools like GitHub Actions. As development processes become increasingly automated and interconnected, the compromise of a single trusted component or account can have a cascading effect across numerous projects and organizations. It highlights the need for continuous vigilance, robust security practices for developer accounts, and thorough scrutiny of automated workflows to prevent credential theft and broader supply chain attacks.

ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

A new malvertising campaign, dubbed "Adception" by security researchers at Push Security, is leveraging Google Ads and Bing redirects to distribute fake Claude installers that deploy "ClickFix" attacks. The campaign was identified after researchers observed malicious Google ads targeting users searching for "claude mac."

cybersecurity

AI Fuels Cybersecurity Mergers and Acquisitions

The cybersecurity industry is currently undergoing a substantial wave of mergers and acquisitions (M&A), with 117 deals reported in the most recent quarter. A key driver behind this heightened activity appears to be the increasing integration of artificial intelligence (AI) across various sectors, leading to a broader range of companies seeking to acquire cybersecurity capabilities.

cloud

AWS AgentCore security undone by prompt requesting credentials

Researchers have identified a critical vulnerability in Amazon Bedrock AgentCore that could allow an attacker to compromise all agents within an AWS account and region by exploiting insufficient network isolation and overly permissive default IAM roles. The flaw, disclosed by Zenity Labs, centers on an attacker's ability to extract temporary AWS credentials from an agent through a single prompt.

ransomware

Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention

German authorities have arrested a Russian national suspected of being a key figure in the Qilin ransomware group. The individual was initially detained in Japan in May while traveling as a tourist in Osaka, following an arrest warrant issued by Germany in connection with a ransomware incident on German soil.

breach

Hundreds of thousands impacted by data breach at biosensor firm iRhythm

Medical device manufacturer iRhythm has confirmed a data breach affecting at least 360,000 individuals, following a cyberattack that occurred in June. The company, known for its Zio Patch cardiac monitoring device, began issuing breach notifications to regulators and victims across multiple states this week.

security

Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty

Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, pleaded guilty in U.S. federal court on Thursday to charges related to his leadership of an international money laundering operation known as Your Mule Cashout (YMCO). The organization, active from 2007 to 2014, utilized a network of over 15,000 unwitting money mules across the United States, Germany, Italy, the United Kingdom,…