CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1319

As cited

Copy frozen at (site build).

threat intel

Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign

A new supply chain campaign exploiting the pull_request_target GitHub workflow has been discovered, attributed to a single actor operating six compromised accounts. The campaign represents a continuation of similar AI-powered attacks, with the attacker active for three weeks before detection. This demonstrates an ongoing threat pattern targeting software development infrastructure.

Why it matters: Software developers and organizations maintaining open source projects or using GitHub workflows are at risk of code injection and supply chain compromise; teams should audit pull request workflows and implement approval controls for pull_request_target triggers.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign

An artificial intelligence (AI)-driven campaign leverages the pull_request_target feature in GitHub Actions to inject malicious code into repositories. Researchers confirm the activity began three weeks prior to detection and trace the attacker to multiple compromised accounts.

Why it matters: Organizations using GitHub Actions with pull_request_target workflows are exposed to supply-chain code execution and should review workflow permissions and restrict untrusted contributions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary