TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39552 162
🔍 Credential-stealing workflows seeded across GitHub repos

Malicious GitHub Actions workflows designed to steal credentials were reportedly planted in tens of thousands of repositories, creating a broad CI/CD supply-chain exposure inside developer environments. The activity abused repository automation, turning trusted build pipelines into collection points for secrets and tokens, as outlined in GitHub Actions workflows.

The significance is scale and access. Compromised workflows can harvest credentials during routine builds, giving attackers a path into codebases, package publishing, and downstream infrastructure without touching endpoint malware.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 10, 2026🔫 Germany arrests alleged core Qilin member after extradition Germany has arrested a Russ…
  2. Oct 10, 2026🔍 US disrupts China-linked Integrity Tech cyber toolset The US Justice Department and FBI…
  3. Oct 10, 2026🔍 AWS AgentCore exposed credentials via agent prompt Researchers from Zenity Labs found t…
  4. Oct 10, 2026🔍 Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks Threat actors…
  5. Oct 10, 2026🔍 Working exploit released for pre-auth AnyDesk Linux root flaw Researchers have publishe…
  6. Oct 10, 2026🔍 SonicWall SMA1000 flaw moves from patch to active exploitation SonicWall SMA1000 applia…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →