340+ GitHub Repos Hacked: How Attackers Stole Credentials

·
Listen to this article~3 min
340+ GitHub Repos Hacked: How Attackers Stole Credentials

A credential-theft campaign compromised two open-source maintainer accounts, planting malicious GitHub Actions workflows in over 340 repositories. Learn how it happened and how to protect your projects.

### The Attack That Hit Over 340 Repositories Imagine waking up to find your open-source project compromised. That's exactly what happened to two well-known maintainers recently. A credential-theft campaign quietly planted malicious GitHub Actions workflows in more than 340 repositories. The attackers didn't need to break down the front door—they simply walked in through trusted accounts. According to StepSecurity, the attacker gained access to the account of Takashi Kitao, the author of the popular game engine pyxel, which has over 18,400 stars. Starting at 13:20 UTC, the attacker pushed a malicious workflow to 27 repositories. But that was just the beginning. The campaign spread like wildfire, eventually affecting hundreds of projects. ### How the Attack Unfolded Here's the scary part: the attack relied on compromised maintainer accounts. Once inside, the attacker added a workflow that stole credentials every time it ran. These workflows are part of GitHub Actions, a tool that automates tasks like testing and deployment. If you're not careful, they can become a backdoor. - The attacker targeted accounts with high trust and broad access. - Malicious workflows were pushed to repositories, often without immediate detection. - Stolen credentials could be used to further compromise other projects or services. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity reported. This quote highlights how quickly a single compromised account can cause widespread damage. ### Why This Matters for Your Projects If you maintain open-source projects, you're a target. Attackers know that maintainers often have access to multiple repositories and sensitive systems. A single stolen token can lead to a supply chain attack that affects thousands of users. Even if you're not a maintainer, you might contribute to projects that use GitHub Actions. The workflows you rely on could be compromised. So, what can you do? - Enable two-factor authentication (2FA) on your GitHub account. - Regularly review your workflows for suspicious activity. - Limit permissions for GitHub Actions to only what's necessary. - Monitor for unusual login activity and revoke tokens if needed. ### The Bigger Picture This isn't the first time attackers have targeted open-source maintainers. As more projects rely on automation, the attack surface grows. It's a reminder that security is a shared responsibility. We all need to stay vigilant. So, next time you push a commit or approve a workflow, take a moment to double-check. Your diligence could prevent the next big breach.