One Actor, Six Identities: How AI Scaled a GitHub Supply Chain Attack

The article details a large-scale supply chain campaign tracked by Wiz in which a single attacker operated six accounts to automate attacks against GitHub repositories. The campaign exploited the pull_request_target workflow to access secrets, using a fully automated pipeline—scan, fork, inject, and submit malicious pull requests. Over 500 attempts were launched, with a low success rate but still resulting in real credential theft. The attacker evolved tactics across waves, eventually using AI-generated, repo-aware payloads. The key takeaway is that AI dramatically lowers the cost and increases the scale of supply chain attacks, even when most attempts fail. 

https://www.wiz.io/blog/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign

Comments

Popular posts from this blog

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Critical OpenSSH Flaws Enable MITM and DoS Attacks

MITRE ATT&CK v19 Redefines How Defenders Model Modern Threats