Tuesday, 02 January 2024 12:17 GMT

Malicious Github Workflows Expose Credentials Across Hundreds Of Repositories Arabian Post


(MENAFN- The Arabian Post) clearfix"> Hackers have compromised hundreds of GitHub repositories by inserting malicious automation workflows designed to steal SSH keys, cloud credentials and access tokens, with security researchers confirming the theft of 26 secrets from 13 repositories.

Cybersecurity company GitGuardian identified 772 affected public repositories belonging to 373 users and organisations during an attack campaign spanning August 31 to September 30. The malicious workflows targeted 2,577 secrets, although the overwhelming majority of attempted thefts did not result in confirmed credential exposure.

The findings, published on October 7 by researchers Gaetan Ferry and Guillaume Valadon, document another wave of the GhostAction supply chain campaign, which exploits compromised developer credentials to insert unauthorised instructions into GitHub Actions, the platform's automated software development system.

MENAFN09102026000152002308ID1111782149



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story