Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Overview
Cybersecurity researchers have reported an ongoing campaign aimed at stealing credentials through malicious workflows on GitHub. Attackers compromised the accounts of two prominent open-source maintainers, including Takashi Kitao, who developed the popular game engine pyxel. Using Kitao's account, the attackers deployed a harmful workflow across 27 repositories. This incident has affected over 340 repositories in total. The implications are serious as it could lead to unauthorized access and exploitation of sensitive data in these projects, raising concerns for developers and users relying on these open-source resources.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: GitHub repositories, specifically those maintained by Takashi Kitao and others involved.
- Action Required: Users should review their repository workflows for unauthorized changes, enable two-factor authentication on their accounts, and monitor for suspicious activity.
- Timeline: Ongoing since October 2023
Original Article Summary
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Impact
GitHub repositories, specifically those maintained by Takashi Kitao and others involved.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since October 2023
Remediation
Users should review their repository workflows for unauthorized changes, enable two-factor authentication on their accounts, and monitor for suspicious activity.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.