Malicious Github Workflows Expose Credentials Across Hundreds Of Repositories Arabian Post
Cybersecurity company GitGuardian identified 772 affected public repositories belonging to 373 users and organisations during an attack campaign spanning August 31 to September 30. The malicious workflows targeted 2,577 secrets, although the overwhelming majority of attempted thefts did not result in confirmed credential exposure.
The findings, published on October 7 by researchers Gaetan Ferry and Guillaume Valadon, document another wave of the GhostAction supply chain campaign, which exploits compromised developer credentials to insert unauthorised instructions into GitHub Actions, the platform's automated software development system.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment