Dissecting the GitHub Actions Attack That Infiltrated 250+ MCP Repositories
A single pull request seemed innocuous—until it revealed a sprawling GitHub Actions supply chain attack across 250+ repos. Attackers used sockpuppet accounts to escalate from awesome lists to token theft.
theAIcatchupApr 08, 20263 min read
⚡ Key Takeaways
Attack spanned 250+ MCP repos in five phases, from awesome lists to OIDC token theft.𝕏
Sockpuppet 'internet-dot' built credibility over months before striking.𝕏
Audit workflows for hashgraph-online/skill-publish; mirrors SolarWinds tactics for AI era.𝕏
The 60-Second TL;DR
Attack spanned 250+ MCP repos in five phases, from awesome lists to OIDC token theft.
Sockpuppet 'internet-dot' built credibility over months before striking.
Audit workflows for hashgraph-online/skill-publish; mirrors SolarWinds tactics for AI era.