GitHub Repositories Compromised in Credential Theft Campaign
Cybersecurity researchers have uncovered the "GhostAction" campaign, which involved the compromise of two high-profile open-source maintainer accounts. This allowed attackers to inject malicious workflows into over 340 GitHub repositories, leading to the exfiltration of sensitive data, including CI/CD, cloud, AI, and SaaS credentials. The incident, which occurred on October 9, 2026, highlights significant supply chain security vulnerabilities for organizations relying on open-source projects and continuous integration systems.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai