A massive credential-stealing campaign has been uncovered on GitHub, with tens of thousands of repositories compromised by malicious workflows. The attack leverages GitHub Actions, a popular automation tool that allows developers to run scripts and deploy code automatically when specific events occur in their repository. Malicious actors have exploited this feature to steal sensitive credentials from affected projects, potentially granting them access to other parts of the victim’s infrastructure.
The attackers created complex workflows that masquerade as legitimate scripts, making it challenging for users to distinguish between malicious and benign actions. These workflows can be triggered by various events, such as pushes to a repository or code reviews. Once activated, they execute a series of commands that extract sensitive credentials from the affected project’s configuration files. The stolen data includes authentication tokens, API keys, and other secrets used to access cloud services like AWS, Azure, and Google Cloud.
The scope of the attack is staggering, with over 50,000 repositories compromised so far. These projects belong to a wide range of organizations and individuals, including some high-profile companies in the tech industry. The attackers appear to be targeting projects that use cloud-based services, suggesting a potential motive of credential laundering – using stolen credentials to access other parts of the victim’s infrastructure.
GitHub has taken steps to mitigate the damage, but users must remain vigilant and review their workflows for any signs of suspicious activity. This attack highlights the importance of secure coding practices and regular security audits. Developers should be cautious when sharing code or collaborating on projects, as malicious actors may use this information to craft targeted attacks.
To protect yourself from similar attacks in the future, ensure that your GitHub Actions workflows are regularly reviewed and updated. Be wary of unfamiliar scripts or configurations, and avoid using third-party libraries without proper vetting. Additionally, implement two-factor authentication (2FA) on all accounts and services that store sensitive credentials. By taking these precautions, you can minimize the risk of credential exposure and prevent attackers from exploiting your infrastructure.
Source: The Hacker News — 2026-10-09