MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #1

GhostAction campaign plants credential-stealing workflows across thousands of GitHub repos

Original: ⚠️ CRITICAL: Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories The GhostAction c

A campaign dubbed GhostAction is compromising GitHub maintainer accounts and injecting malicious Actions workflows into tens of thousands of repositories. The injected workflows are designed to steal secrets such as API keys, tokens, and other credentials from the affected projects. Security researchers are urging maintainers to audit their workflow files, rotate exposed secrets, and review repository permissions, as the malicious code can run automatically in CI environments where sensitive tokens are routinely available.

Why now: News of a large-scale, active supply-chain attack on GitHub repositories is alarming developers who rely on GitHub Actions for their builds.

GitHubGitHub ActionsGhostAction

Open on mastodon →

Rank over time, top of the chart is #1. 2 snapshots from 4 h ago to 4 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1727566