Cybersecurity · October 10, 2026
Researchers have uncovered an active supply-chain attack in which hijacked accounts belonging to prominent open-source maintainers were used to inject a malicious GitHub Actions workflow into hundreds of repositories, aiming to steal developer credentials. One compromised account belonged to the creator of the popular pyxel game engine, and security firm StepSecurity says the attacker began pushing the rogue workflow to dozens of that project's repositories in rapid succession. The campaign is a reminder that a single stolen maintainer login can cascade across tens of thousands of downstream projects that depend on these packages.
// source: thehackernews.com ↗