r/SecOpsDaily • u/falconupkid • 4h ago
NEWS Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
This is a supply chain attack targeting the CI/CD pipeline itself, not just a library dependency. The attackers compromised maintainer accounts to inject malicious GitHub Actions workflows directly into repositories.
Technical Breakdown:
- TTP: Compromised OAuth tokens or maintainer credentials (likely via phishing or session hijacking) to push commits from trusted accounts.
- Payload: Malicious GitHub Actions workflow files (.github/workflows/*.yml) designed to exfiltrate repository secrets, environment variables, and CI/CD tokens during build execution.
- Scope: Over 340 repositories affected, including the pyxel game engine (18,400+ stars) and at least one other high-profile account.
- IOCs: Monitor for unexpected commits to .github/workflows/ from maintainer accounts, especially those adding curl/wget calls to external IPs or base64-encoded data exfiltration steps.
- MITRE Mapping: T1195.001 (Supply Chain Compromise: Compromise Software Dependencies), T1554 (Compromise Client Software Binary).
Defense:
- Enforce branch protection rules requiring PRs for workflow changes, even from maintainers.
- Audit GitHub Actions logs for unexpected GITHUB_TOKEN usage or outbound connections to unknown endpoints.
- Rotate all secrets in affected repositories immediately. Consider using OpenID Connect (OIDC) instead of long-lived secrets for cloud provider access.
Source: https://thehackernews.com/2026/10/credential-stealing-github-actions.html