Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, t...
**Source : The Hacker News | 10 octobre 2026**
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
"Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
👉 **Lire l'article complet sur The Hacker News :** [https://thehackernews.com/2026/10/credential-stealing-github-actions.html](https://thehackernews.com/2026/10/credential-stealing-github-actions.html)
Commentaires (0)
Laisser un commentaire
Aucun commentaire pour le moment. Soyez le premier à commenter !