Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers found malicious GitHub Actions workloads injected into over 340 repositories, compromising two high-profile open-source maintainer accounts.
Intelligence analysis by Qwen 2.5 (3B)

Cybercriminals have injected malicious GitHub Actions workloads into over 340 repositories, compromising two high-profile open-source maintainer accounts. The workloads are designed to exfiltrate sensitive data to a hard-coded IP address.
Bad guys got into a GitHub account and put a sneaky program in a code file. This program steals important information and sends it to the bad guys. Developers need to look for this sneaky program and fix it to keep their data safe.
Analysis
{"heading_1":"The Attack Chain","subheading_1":"Credential Theft","content_1":"The attackers obtained the maintainer's GitHub credentials, likely through leaked personal access tokens (PATs) or credential dumps.","subheading_2":"Reconnaissance","content_2":"The attackers scanned the repository's workflow files for secrets and injected a malicious workflow named 'Security Audit' or 'GitHub Actions Security'.","subheading_3":"Data Exfiltration","content_3":"The malicious workflow triggers on workflow_dispatch and an unfiltered push, extracts data, and sends it to an attacker-controlled endpoint via curl.","subheading_4":"Impact","content_4":"The attack resulted in the exfiltration of 3,325 secrets, including AWS keys, API keys, and GitHub and GitLab tokens. The malicious workflows were also used to deploy a cryptocurrency miner in a Docker image.","subheading_5":"Prevention","content_5":"Developers are advised to check their repositories for the malicious workflows and assume compromise if present. They should revoke compromised credentials, rotate credentials, delete the malicious workflow, and check forks of the infected repositories."}
Key points
- Malicious GitHub Actions workloads were injected into over 340 repositories.
- The workloads are designed to exfiltrate sensitive data to a hard-coded IP address.
- The attack resulted in the exfiltration of 3,325 secrets, including AWS keys, API keys, and GitHub and GitLab tokens.
- Developers are advised to check their repositories for the malicious workflows and take steps to secure their credentials.
Developers can prevent this by checking their repositories for the malicious workflows and taking steps to secure their credentials.
If developers don't check their repositories, the bad guys could still steal their data.



