Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #1
GhostAction campaign plants credential-stealing workflows across thousands of GitHub repos
Original: ⚠️ CRITICAL: Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories The GhostAction c
A campaign dubbed GhostAction is compromising GitHub maintainer accounts and injecting malicious Actions workflows into tens of thousands of repositories. The injected workflows are designed to steal secrets such as API keys, tokens, and other credentials from the affected projects. Security researchers are urging maintainers to audit their workflow files, rotate exposed secrets, and review repository permissions, as the malicious code can run automatically in CI environments where sensitive tokens are routinely available.
Why now: News of a large-scale, active supply-chain attack on GitHub repositories is alarming developers who rely on GitHub Actions for their builds.
GitHubGitHub ActionsGhostAction
Rank over time, top of the chart is #1. 2 snapshots from 8 h ago to 8 h ago.
Evidence
- ⚠️ CRITICAL: Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories The GhostAction campaign is actively compromising GitHub maintainer accounts and injecting malicious workflows into thousands of repositories to steal API keys, tokens, and… · threatnoir@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1727566