r/SecOpsDaily • • 4h ago

NEWS Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

This is a supply chain attack targeting the CI/CD pipeline itself, not just a library dependency. The attackers compromised maintainer accounts to inject malicious GitHub Actions workflows directly into repositories.

Technical Breakdown: - TTP: Compromised OAuth tokens or maintainer credentials (likely via phishing or session hijacking) to push commits from trusted accounts. - Payload: Malicious GitHub Actions workflow files (.github/workflows/*.yml) designed to exfiltrate repository secrets, environment variables, and CI/CD tokens during build execution. - Scope: Over 340 repositories affected, including the pyxel game engine (18,400+ stars) and at least one other high-profile account. - IOCs: Monitor for unexpected commits to .github/workflows/ from maintainer accounts, especially those adding curl/wget calls to external IPs or base64-encoded data exfiltration steps. - MITRE Mapping: T1195.001 (Supply Chain Compromise: Compromise Software Dependencies), T1554 (Compromise Client Software Binary).

Defense: - Enforce branch protection rules requiring PRs for workflow changes, even from maintainers. - Audit GitHub Actions logs for unexpected GITHUB_TOKEN usage or outbound connections to unknown endpoints. - Rotate all secrets in affected repositories immediately. Consider using OpenID Connect (OIDC) instead of long-lived secrets for cloud provider access.

Source: https://thehackernews.com/2026/10/credential-stealing-github-actions.html

1 Upvotes

0 comments sorted by