Hackers Just Hijacked GitHub Accounts to Steal Credentials From 340+ Repos
Emily Davis ·
Listen to this article~4 min
Cybersecurity researchers have uncovered a credential-theft campaign that compromised two high-profile open-source maintainer accounts, pushing malicious workflows into over 340 repositories. One victim was the author of the popular pyxel game engine.
Imagine waking up to find that someone used your GitHub account to push malicious code into dozens of repositories overnight. That's exactly what happened to two well-known open-source maintainers recently, and it's a wake-up call for anyone who contributes to open source.
### What Exactly Happened?
Security researchers have uncovered an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts. The attackers used these accounts to push a malicious workflow into over 340 repositories. One of the victims was Takashi Kitao, the author of pyxel, a popular game engine with 18,400 stars on GitHub.
According to StepSecurity, the attacker used Kitao's account to push a malicious workflow to 27 repositories starting at 13:20 UTC. That's a lot of damage in a short amount of time.
### How Did They Pull It Off?
The attack likely started with stolen credentials. Once the attackers had access to the maintainer's account, they could push changes to any repository the maintainer had write access to. In this case, they added a workflow that would steal credentials from anyone who ran it.
> "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC." — StepSecurity
But this wasn't just about one account. The campaign affected over 340 repositories, meaning the attackers had access to multiple accounts or found a way to propagate the malicious workflow.
### Why Should You Care?
If you're a developer, you're probably using GitHub Actions or similar CI/CD tools. These workflows run with your credentials and can access your repositories, secrets, and more. If a malicious workflow gets into a repository you contribute to, it could steal your credentials too.
Here's what you can do to protect yourself:
- Enable two-factor authentication (2FA) on your GitHub account. It's a simple step that blocks most credential-stuffing attacks.
- Regularly review your repository's workflows. Look for any unexpected changes or new workflows you didn't add.
- Limit access. Only give write access to people who absolutely need it.
- Use a password manager. It helps you create and store strong, unique passwords.
- Monitor your account activity. GitHub sends alerts for new logins, so pay attention to them.
### The Bigger Picture
This incident highlights a growing trend: attackers are targeting the software supply chain. By compromising a single maintainer, they can potentially infect thousands of projects. It's a reminder that security is everyone's responsibility, not just the maintainers.
Open-source maintainers often work alone, without the resources of a large security team. That makes them attractive targets. As a community, we need to support them by following best practices and being vigilant.
### What's Next?
The researchers are still investigating the full scope of the campaign. GitHub has since removed the malicious workflows, but the attackers may try again. It's a good time to audit your own security practices.
Remember, your credentials are valuable. Don't make it easy for attackers. Stay safe out there.