Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

0 Replies 1 Views
Raters
Participants
Thread Starter #1
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.

"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity

Okumaya devam et...

You must be logged in to reply.

Users who are viewing this thread (Total: 2, Members: 2, Guests: 0)
Total: 2 (members: 2, guests: 0)
0 quotes selected