MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via The Hacker News

Compromised Maintainer Accounts Used to Spread Malicious GitHub Workflows

Image via The Hacker News
Image via The Hacker News

Security researchers have uncovered an active operation that steals credentials through malicious GitHub Actions workflows. Attackers took over two prominent open-source maintainer accounts, including that of pyxel creator Takashi Kitao, and used one to push a harmful workflow to 27 repositories. The broader campaign has reached more than 340 repositories, according to StepSecurity.

Expanded Detail

Security researchers say an ongoing effort is abusing GitHub Actions workflows to harvest credentials. The operation involved two well-known open-source maintainer accounts, among them Takashi Kitao, the creator of pyxel. One compromised account was used to distribute a harmful workflow across 27 repositories. StepSecurity reports that the wider campaign has affected over 340 repositories, underscoring how trusted maintainer access can be turned into a vector for supply-chain attacks.

Context

The compromise could affect developers and organizations relying on the impacted repositories, potentially exposing credentials and enabling further intrusions. Because open-source maintainers often hold broad access, attackers may exploit that trust to reach downstream users. The incident may prompt teams to review workflow permissions, monitor repository changes, and strengthen account protections. It could also raise broader concerns about the security of automation in software development.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories.” Browse more stories.