Credential‑Stealing GitHub Actions Workflows Planted in Over 340 Repositories
What Happened — Researchers observed a credential‑theft campaign that hijacked two high‑profile open‑source maintainer accounts and used them to push malicious GitHub Actions workflows into 340+ repositories. The malicious workflow is designed to capture secrets stored in the CI environment and exfiltrate them to attacker‑controlled servers.
Why It Matters for Trust & Control Assurance
- Demonstrates how compromised privileged accounts can bypass traditional perimeter defenses, highlighting the need for continuous monitoring of identity and access controls.
- Shows the risk of supply‑chain contamination through CI/CD pipelines; a control‑assurance program must capture evidence of workflow changes and enforce policy compliance.
- Provides a real‑world example where a single lapse in credential hygiene can affect thousands of downstream projects, underscoring the importance of auditable credential‑management processes.
Who Is Affected – Open‑source maintainers, SaaS developers, and any organization that relies on GitHub Actions for CI/CD.
Recommended Actions –
- Enforce MFA and enforce strong password policies for all GitHub accounts with write access.
- Implement least‑privilege repository permissions; restrict who can add or modify GitHub Actions workflows.
- Deploy continuous monitoring of workflow changes and secret usage; generate immutable audit logs for any workflow push.
- Rotate any exposed secrets immediately and scan repositories for malicious workflow files.
Source: The Hacker News
Technical Notes – The attackers leveraged stolen OAuth tokens from the compromised maintainer accounts to create a malicious workflow that runs on every push, harvesting GITHUB_TOKEN, AWS_ACCESS_KEY_ID, and other CI secrets. No specific CVE is involved; the vector is credential compromise and supply‑chain abuse.
Source: The Hacker News