IncidentAttackers Turned GitHub Actions Into a Credential Harvester
Between July 12 and 13, 2026, attackers compromised ten Packagist packages tied to a legitimate PHP developer s account. They injected 583 malicious GitHub Actions workflow files across those packages














