Security
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
The Hacker News·October 9, 2026·1 min read
Researchers disclosed a credential-theft campaign that compromised two high-profile open-source maintainer accounts, pushing malicious workflows into over 340 repositories. Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC, according to StepSecurity.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
