Malicious GitHub Actions Workflows Target Developer Credentials Across Repositories
Security researchers have uncovered a GhostAction campaign using malicious GitHub Actions workflows to steal credentials from thousands of repositories through compromised maintainer accounts.