Cybersecurity researchers discovered an active credential-theft campaign targeting open-source repositories through compromised maintainer accounts. The attackers leveraged hijacked credentials to inject malicious GitHub Actions workflows into over 340 repositories.
The campaign exploited the account of Takashi Kitao, maintainer of pyxel, a game engine project with 18,400 GitHub stars. Starting at 13:20 UTC, the attacker used Kitao's compromised account to push malicious workflows across 27 repositories. StepSecurity disclosed the details of this ongoing attack.
GitHub Actions workflows execute automated tasks within repositories. When attackers inject malicious workflows into active projects, they gain code execution capabilities within the CI/CD pipeline. This access enables theft of credentials, secrets, and environment variables stored in repository settings or CI/CD systems.
The scale of this campaign, affecting over 340 repositories through at least two compromised maintainer accounts, demonstrates the attackers' focus on high-visibility open-source projects. Developers who fork or depend on compromised repositories risk inheriting the malicious workflows into their own environments.
Credential theft remains a primary attack vector for compromising development infrastructure. Open-source maintainers face elevated risk because their accounts control widely-used code repositories. Attackers who gain access to these accounts can distribute malicious code to thousands of developers through workflow injections.
The campaign highlights the importance of credential security for open-source maintainers and the need for repository-level protections. GitHub Actions workflows should be reviewed for unexpected changes, and maintainers should implement strong authentication controls, including multi-factor authentication and limited-scope access tokens. Developers using open-source dependencies should verify the integrity of workflows executed in their environments and monitor for suspicious CI/CD activity.
