Compromised Maintainer Accounts Used to Spread Malicious GitHub Workflows

Security researchers have uncovered an active operation that steals credentials through malicious GitHub Actions workflows. Attackers took over two prominent open-source maintainer accounts, including that of pyxel creator Takashi Kitao, and used one to push a harmful workflow to 27 repositories. The broader campaign has reached more than 340 repositories, according to StepSecurity.
Security researchers say an ongoing effort is abusing GitHub Actions workflows to harvest credentials. The operation involved two well-known open-source maintainer accounts, among them Takashi Kitao, the creator of pyxel. One compromised account was used to distribute a harmful workflow across 27 repositories. StepSecurity reports that the wider campaign has affected over 340 repositories, underscoring how trusted maintainer access can be turned into a vector for supply-chain attacks.
The compromise could affect developers and organizations relying on the impacted repositories, potentially exposing credentials and enabling further intrusions. Because open-source maintainers often hold broad access, attackers may exploit that trust to reach downstream users. The incident may prompt teams to review workflow permissions, monitor repository changes, and strengthen account protections. It could also raise broader concerns about the security of automation in software development.