Mass GitHub Actions Campaign Steals Cloud Keys From Tens of Thousands of Repositories
More than 500 GitHub accounts have pushed malicious Actions workflows into tens of thousands of repositories, harvesting AWS keys, API tokens and other secrets from developers under the guise of security audits.
A large credential‑theft operation is turning GitHub’s own automation tools into a path into developers’ cloud environments.
Security research cited in a new report describes more than 500 GitHub accounts that either were compromised or created for abuse and then used to commit malicious GitHub Actions workflows to tens of thousands of repositories. The workflows were presented as code security audits but were designed to capture sensitive information, including AWS access keys, API tokens and other secrets lurking in code history or build environments.
GitHub Actions is the service that lets projects automatically test, build and deploy software when code changes are pushed. Many organizations rely on it as part of their continuous integration and deployment pipelines. By modifying these workflows, attackers can tap into automated processes that run with whatever permissions developers grant them.
In this campaign, those behind it didn’t have to breach GitHub’s core infrastructure. They spread their malicious workflows widely, increasing the odds that maintainers would enable or reuse them with minimal scrutiny. Once activated, the code scanned repositories and environments for credentials and sent any collected secrets to servers controlled by the attackers.
For development and operations teams, the implications are serious. If an AWS key or production API token leaks from a build pipeline, it can give an outsider direct access to cloud resources. That access can be used for data theft, deployment of ransomware, unauthorized cryptocurrency mining or planting backdoors in software components that others depend on.
The sheer number of affected repositories points to a broader supply‑chain risk. Each compromised project may sit inside a larger web of dependencies for other applications and services. A successful attack on one workflow can therefore expose downstream users who never interact with the attacker’s code directly but inherit its effects through normal software updates.
Cloud platforms also face knock‑on pressure when many working credentials are stolen in parallel. Attackers can distribute their activity across multiple victim accounts, making it harder for defenders to spot abnormal behavior and cut off access quickly.
The method is a reminder that the scripts and configuration files that tie modern development environments together need the same level of protection as the applications themselves.
In the near term, defenders will have to find and remove malicious workflows, rotate any exposed keys and restrict which Actions are allowed to run in their projects. How quickly GitHub can identify and quarantine tainted accounts and workflows, whether cloud providers see a rise in suspicious activity linked to newly exposed keys and whether similar abuse turns up on other code‑hosting platforms will show how far this campaign has already spread and how much the model might be copied.
Sources
- OSINT