Credential‑Stealing GitHub Actions Workflows Inserted into 340+ Repositories via Compromised Maintainer Accounts
Researchers uncovered a campaign that hijacked two open‑source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories, stealing CI secrets. The incident highlights the need for continuous identity‑access monitoring and auditable CI/CD controls for compliance readiness.
ADTP Breach Watch· October 9, 2026· The Hacker News
Two high‑profile open‑source maintainer accounts were compromised and used to push malicious GitHub Actions workflows into 340+ repositories. The workflows capture CI secrets and exfiltrate them to attacker‑controlled endpoints.
Why it matters for trust and compliance
This scenario illustrates why continuous control‑assurance over privileged identities and CI/CD pipeline changes is essential for audit readiness and defensible evidence.
Demonstrates the need for continuous monitoring of privileged account activity and workflow changes.
Provides evidence that robust credential‑management and least‑privilege policies are critical control objectives across frameworks.