Credential-Stealing GitHub Actions Workflows Compromise 340+ Repositories

A newly uncovered credential-theft campaign has compromised over 340 open-source repositories by exploiting maintainer accounts to inject malicious GitHub Actions workflows. According to research from StepSecurity, the attackers gained control of two high-profile maintainer accounts—including that of Takashi Kitao, author of the popular 18,400-star game engine pyxel—and used them to push malicious workflows starting at 13:20 UTC on October 9, 2026. The campaign highlights the growing risk of supply chain attacks targeting CI/CD pipelines.

How the Attack Unfolded

The attackers leveraged compromised personal access tokens or session cookies to authenticate as legitimate maintainers. Once inside, they added or modified GitHub Actions workflow files (typically in .github/workflows/) to execute malicious code during routine CI/CD runs. These workflows exfiltrated sensitive credentials—such as cloud API keys, database passwords, and deployment tokens—to attacker-controlled servers.

StepSecurity’s analysis indicates that the malicious workflow was planted in at least 27 repositories under Kitao’s account alone, with the total number of affected repositories exceeding 340 across multiple maintainers. The campaign appears to be ongoing, with new repositories being targeted as attackers gain access.

Why GitHub Actions Is a Prime Target

GitHub Actions has become a cornerstone of modern software development, automating build, test, and deployment processes. However, its tight integration with repository secrets and cloud environments makes it an attractive target for attackers. A single compromised workflow can:

  • Steal repository secrets and environment variables.
  • Access cloud provider credentials (AWS, Azure, GCP) configured for deployments.
  • Modify source code or inject backdoors into build artifacts.
  • Pivot to other repositories owned by the same organization or maintainer.

The attack is reminiscent of previous supply chain incidents, such as the 2025 tj-actions/changed-files compromise, where attackers modified a popular action to exfiltrate secrets from thousands of repositories.

The pyxel Connection

Takashi Kitao’s pyxel is a widely used retro game engine with a large community. Its popularity made Kitao a high-value target. The attackers likely gained access through a phishing campaign, credential stuffing, or a compromised third-party service. Once in control, they pushed malicious workflows to repositories that Kitao maintained, potentially affecting downstream users who rely on those projects.

StepSecurity reported that the malicious workflow was designed to run on push and pull_request events, ensuring it executed frequently. The workflow used obfuscated scripts to avoid detection and exfiltrated data via HTTPS to domains registered recently.

Scope and Impact

While the exact number of compromised repositories is still being tallied, the campaign’s breadth—over 340 repositories—suggests a coordinated effort. The attackers may be financially motivated, selling stolen credentials on dark web markets, or seeking to compromise software supply chains for further attacks.

Organizations and individual developers using affected repositories should immediately:

  • Audit GitHub Actions workflows for unauthorized changes.
  • Rotate all secrets and tokens that may have been exposed.
  • Review audit logs for suspicious activity, such as new workflow files or unexpected workflow_dispatch events.
  • Enable branch protection and require pull request reviews for workflow changes.

Mitigation and Best Practices

To defend against similar attacks, security experts recommend:

  • Use short-lived tokens instead of long-lived personal access tokens.
  • Implement least privilege for GitHub Actions, limiting GITHUB_TOKEN permissions.
  • Pin actions to specific commit SHAs rather than tags to prevent tag-based supply chain attacks.
  • Monitor workflow runs with tools like StepSecurity, which can detect anomalous behavior.
  • Enable 2FA and use hardware security keys for maintainer accounts.
  • Regularly rotate secrets and use secret scanning to detect leaks.

GitHub has been notified of the campaign and is reportedly investigating. The company has previously introduced features like GITHUB_TOKEN scoping and workflow approval for first-time contributors, but attackers continue to find gaps.

The Bigger Picture

This incident underscores the fragility of open-source supply chains. A single compromised maintainer can affect hundreds of projects and thousands of downstream users. As CI/CD pipelines become more powerful, they also become more dangerous if not properly secured.

Developers and organizations must treat their GitHub Actions workflows as critical security assets. Regular audits, strict access controls, and continuous monitoring are no longer optional—they are essential.

For more details, read the original report on The Hacker News.