Security researchers have disclosed an active supply-chain attack in which threat actors hijacked high-profile open-source maintainer accounts to distribute a credential-stealing GitHub Actions workflow. According to StepSecurity, the malicious workflow has been pushed to more than 340 repositories so far, with the campaign still unfolding.

One of the compromised accounts belongs to Takashi Kitao, maintainer of pyxel, a popular retro game engine with roughly 18,400 stars on GitHub. Using Kitao’s account, the attacker pushed the malicious workflow to 27 repositories starting at 13:20 UTC, researchers said. A second high-profile maintainer account was also reportedly compromised and used in the same campaign.

How the Attack Works

By taking over legitimate maintainer accounts rather than relying on typosquatting or fake packages, the attackers were able to inject malicious GitHub Actions workflows directly into trusted repositories. Because the workflows originate from accounts with established reputations and commit histories, downstream users and automated systems are less likely to flag the changes as suspicious.

GitHub Actions workflows run with access to repository secrets, environment variables, and in many cases, tokens that can be used to authenticate to other services. A compromised workflow can be configured to exfiltrate these credentials to an attacker-controlled endpoint, potentially giving the threat actor a foothold for further supply-chain compromise across dependent projects.

Why It Matters

The scale of this campaign, affecting tens of thousands of repositories according to researchers tracking the incident, underscores the risk posed by CI/CD pipeline compromise in the open-source ecosystem. Maintainer account takeovers are particularly dangerous because they bypass the trust signals that developers and automated scanners typically rely on, such as commit signing reputation and repository history.

Organizations that depend on open-source packages affected by this campaign should audit their GitHub Actions workflow logs for unauthorized changes, rotate any secrets or tokens exposed to affected repositories, and review recent commits to maintainer-controlled projects in their dependency tree. Enabling branch protection rules, requiring signed commits, and restricting workflow permissions to the minimum necessary are also recommended mitigations as this investigation continues.