Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Contenu original affiche; la traduction localisee n'est pas encore disponible.
Ce qui s'est passé
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Pourquoi c'est important
The development may change operating conditions or market expectations around Security. Further confirmation and measurable outcomes matter.
Entités concernées
Voir les preuves
1 articles · 1 publication d'origine · 1 independantes
- The Hacker NewsSource primaire · Confirme · EN · 100%Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories ↗
Affirmations
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories Observé
Divergences
Aucune divergence importante détectée dans les preuves disponibles.
Chronologie
- Premier signalement
Mouvement de marché suivant l'événement
La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.