step-security · Crawled Jul 22, 2026
Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization
1 Malware
Read original article ↗
AI Summary
Threat actors are increasingly targeting GitHub Actions secrets through campaigns like GhostAction and Megalodon, which exfiltrated thousands of secrets from public repositories. These attacks exploit the accumulation of unused, stale, or long-lived credentials that organizations fail to clean up. The Shai-Hulud worm exemplifies the risk, spreading by stealing npm tokens to publish malicious packages. Transitioning to OIDC-based authentication and eliminating unused secrets can reduce the attack surface significantly.
AI-extracted · verify before operational use