HackerFeeds

CyberSecurity News

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

The Hacker News
· October 9, 2026

AI summary

Cybersecurity researchers have uncovered a credential theft campaign that has compromised high-profile open-source maintainer accounts. The attackers used these accounts to push a malicious workflow into numerous repositories, with one instance involving the account of Takashi Kitao, author of the pyxel game engine. The malicious workflow was pushed to 27 repositories, starting at a specific time. This campaign has affected over 340 repositories in total. The attackers' goal is to steal credentials. The malicious activity was detected and disclosed by researchers.

Read the full article at The Hacker Newsthehackernews.com/2026/10/credential-stealing-github-actions.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.