Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Cybersecurity · October 10, 2026

Cybersecurity·thehackernews.com

Researchers have uncovered an active supply-chain attack in which hijacked accounts belonging to prominent open-source maintainers were used to inject a malicious GitHub Actions workflow into hundreds of repositories, aiming to steal developer credentials. One compromised account belonged to the creator of the popular pyxel game engine, and security firm StepSecurity says the attacker began pushing the rogue workflow to dozens of that project's repositories in rapid succession. The campaign is a reminder that a single stolen maintainer login can cascade across tens of thousands of downstream projects that depend on these packages.

// source: thehackernews.com ↗

← Back to Blog