跳到正文
原文
The Hacker News· [email protected] (The Hacker News)·本站收录 · 原文发表

GhostAction 攻击向数万个 GitHub 仓库植入窃取凭证的 Actions workflow

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

AI 导读

StepSecurity 和 Socket 披露,GhostAction 供应链攻击活动通过两个高知名度开源维护者账号,向 340 多个仓库推送了恶意 GitHub Actions workflow。攻击者疑似利用信息窃取日志中泄露的 PAT 获取维护者账号,随后注入名为 security-audit.yml 或 github_actions_security.yml 的 workflow,通过 curl 以明文 HTTP 将数据外传到硬编码 IP 193.32.204[.]199。窃取内容包括仓库的 GitHub Actions secrets、CI/CD 凭证,以及工作树和完整 git 历史中的 AWS、Anthropic、OpenAI、OpenRouter API key 和 GitHub、GitLab token。

阅读原文thehackernews.com