The Hacker News reports that attackers have compromised open-source maintainer accounts to push a malicious GitHub Actions workflow into more than 340 repositories, with more than 500 GitHub accounts affected since October 7. The workflow is designed to steal secrets, including cloud, SaaS and AI credentials. Developers should check for the named workflows, revoke compromised GitHub credentials, rotate secrets, and delete the malicious workflow from all branches.
Source: thehackernews.com
Share
…


