Compromised Maintainer Accounts Used to Push Credential-Stealing GitHub Actions Workflows to 340+ Repos
What happened
Researchers at StepSecurity have disclosed an ongoing credential-theft campaign in which attackers compromised the accounts of at least two high-profile open-source maintainers and used them to push a malicious GitHub Actions workflow into over 340 repositories. One of the compromised accounts belongs to Takashi Kitao, author of the 18,400-star game engine pyxel; using his account, the attacker pushed the malicious workflow to 27 repositories starting at 13:20 UTC. The campaign reportedly reaches tens of thousands of repositories in total, though full scope and the initial access method used to compromise the maintainer accounts have not yet been detailed in the reporting available.
Why it matters for defenders
GitHub Actions workflows run with access to repository secrets, including deployment credentials, package-registry tokens, and cloud API keys, so a malicious workflow injected via a trusted maintainer's account can harvest and exfiltrate those secrets before anyone notices the commit looks wrong. Because the pushes come from legitimate, high-reputation maintainer accounts, downstream consumers of affected repositories — including CI pipelines and dependent projects that pull in these repos as dependencies — are also at risk of a supply-chain ripple effect. Any organization that consumes open-source packages or game-engine components like pyxel should treat this as a reminder that trust in a maintainer's identity does not guarantee trust in every commit.
What defenders should watch for or do now
- Audit recent commits and workflow file changes (
.github/workflows/) across repositories you maintain or depend on, especially pushes from maintainer accounts outside their normal commit patterns or hours. - Review GitHub Actions run logs for unexpected outbound network calls, unfamiliar third-party actions, or workflows added/modified without a corresponding pull request.
- Rotate and scope down repository and organization secrets, enforce least-privilege on
GITHUB_TOKENpermissions, and require workflow approval for first-time or external contributors. - Enable branch protection and required reviews on workflow file changes, and consider pinning actions to commit SHAs rather than mutable tags.
- Encourage maintainers to enable hardware-backed MFA and monitor for anomalous sign-ins, since this campaign appears rooted in account compromise rather than a code vulnerability.
Developing story
Details on the attackers' initial access method, full victim count, and exfiltration infrastructure are still emerging. This is net-new, CVE-less intel based on current reporting — treat the specifics as provisional and consult the original coverage for updates: The Hacker News.