Between 8 and 11 July 2023, an attacker pushed malicious commits to hundreds of GitHub repositories, public and private, dressed up to look like routine updates from Dependabot, GitHub's automated dependency tool. The commits were titled "fix" and attributed to "dependabot[bot]", so developers who trusted the bot might not look closely. Checkmarx, which detected them, confirmed with victims that the attacker had used their stolen GitHub personal access tokens (PATs). Each malicious commit added a GitHub Actions workflow that sent the project's secrets and variables to an attacker server on every push, and appended code to every JavaScript file to steal passwords typed into web forms. Most victims were Indonesian accounts. How the tokens were stolen is unknown; Checkmarx suspects malicious packages on developers' machines.
Key takeaways
- The attacker used stolen GitHub personal access tokens, which work without two-factor authentication, to push code as the victims.
- Commits were faked to appear as Dependabot "fix" contributions, exploiting developers' trust in automation.
- A new workflow file, hook.yml, sent each project's GitHub secrets and variables to an attacker server on every push, according to Checkmarx.
- Every JavaScript file was modified to load a script that captured passwords from web forms, turning victims' projects into credential stealers for their users.
- The identity lesson: a developer's PAT is a standing credential that bypasses MFA, and CI/CD secrets are only as safe as every token that can edit a workflow.
At a glance
| Organisations | Hundreds of GitHub account holders and organisations, mostly Indonesian accounts; GitHub (Dependabot impersonated) |
|---|---|
| When | Malicious commits 8 to 11 July 2023; disclosed by Checkmarx 27 September 2023 |
| Attacker | Unattributed |
| Entry point | Stolen GitHub personal access tokens, probably taken from developers' machines |
| Identities abused | Victims' GitHub PATs; the Dependabot bot identity, impersonated in commit metadata; GitHub Actions secrets and variables in affected repositories |
| Impact | Malicious code pushed to hundreds of public and private repositories; project secrets exfiltrated on push; end-user passwords targeted by injected JavaScript |
| Category | NHI. Incident class: confirmed NHI breach (stolen tokens used to steal CI/CD secrets) |
What happened
"In July 2023, our scanners detected nontypical commits to hundreds of GitHub repositories appeared to be contributed by Dependabot and carrying malicious code," Checkmarx wrote. "Between July 8-11 a threat actor started compromising hundreds of GitHub repositories, both public and private. Most victims are Indonesian user accounts." The commits were titled "fix" and made to look as if they came from the "dependabot[bot]" account. Checkmarx said this was "the first incident we witnessed a threat actor using fake git commits to disguise activity, knowing that many developers do not check the actual changes of dependabot when they see it."
The changes followed two automated patterns. First, a new GitHub Actions workflow named hook.yml, triggered on every push, sent the repository's GitHub secrets and variables to send[.]wagateway[.]pro. Second, every existing .js file gained an obfuscated line that loaded a remote script designed to intercept password fields in web forms and send the credentials to the same server. Because some victims' tokens also had access to private organisation repositories, those were hit too.
Checkmarx contacted victims and, with those who shared account activity, found the attacker "accessed the accounts using compromised PATs (Personal Access Token)", which it said were most likely exfiltrated silently from the victims' development environments. It noted that such tokens are stored locally, "do not require 2FA and can be used to access the account by any computer with internet access." It could only guess at how they were stolen, suggesting "the most likely scenario is that the victims were infected with such a malicious package." BleepingComputer and SecurityWeek reported the findings on 27 September 2023.
Timeline
| Date | Event |
|---|---|
| 8 July 2023 | Between 8 and 11 July, the attacker compromises hundreds of repositories with fake Dependabot commits, according to Checkmarx. |
| 27 September 2023 | Checkmarx publishes its analysis; BleepingComputer and SecurityWeek report it. |
How it happened: the identity attack path
- Tokens stolen from developers. Personal access tokens stored on developers' machines were exfiltrated, possibly by malicious packages.
- MFA bypassed by design. The tokens authenticated to GitHub without any second factor.
- Automation impersonated. Scripts pushed commits labelled "fix" and attributed to dependabot[bot] to avoid scrutiny.
- Secret-stealing workflow added. A hook.yml workflow exfiltrated the repository's Actions secrets and variables on every push.
- Downstream credential theft. Injected JavaScript captured passwords from end users of the affected projects.
Impact
- Repositories: hundreds of public and private repositories modified, mostly belonging to Indonesian accounts.
- Secrets: GitHub Actions secrets and variables sent to the attacker on push.
- End users: passwords entered into web forms served by affected projects were targeted.
What this means for NHI governance
Two machine identities were abused here. The first was the developer's PAT: a long-lived bearer token that acts as the developer without MFA and can often reach every repository the developer can. The second was the bot identity: Dependabot is trusted precisely because it is automated, and the attacker borrowed that trust by faking its name in commit metadata.
The payload shows why CI/CD secrets need protection beyond the repository. Anyone who can add a workflow can read every secret that workflow can access. Fine-grained, expiring tokens, signed commits, branch protection that requires review of workflow changes, and secrets scoped to protected environments would each have limited the damage. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.
Recommendations
- Replace classic PATs with fine-grained, expiring tokens. Limit each token to the repositories and permissions it needs. See the CI/CD Pipeline Identity Security Guide.
- Require review for workflow changes. Use branch protection and code owners so new or modified workflow files cannot merge unreviewed.
- Verify commit authorship. Require signed commits and treat unsigned commits claiming to be from bots as suspicious.
- Scope Actions secrets to protected environments. Secrets should not be available to any workflow on any push. See our Secrets Management Guide.
- Protect developer machines from malicious packages. Token theft from workstations is a common start of supply chain attacks. See the Leaked Credential Response Playbook.
Frequently asked questions
What was the fake Dependabot attack?
In July 2023 an attacker used stolen GitHub personal access tokens to push malicious commits to hundreds of repositories, disguising them as Dependabot updates. The code stole project secrets and end users' web-form passwords.
How did attackers get into the GitHub accounts?
Checkmarx confirmed with victims that stolen personal access tokens were used. These tokens bypass 2FA. How they were stolen is unknown; Checkmarx suspects malicious packages on developers' computers.
How can teams spot fake Dependabot commits?
Real Dependabot changes arrive as pull requests from the bot, not direct commits by a user. Check commit signatures, review any change to workflow files, and look for unexpected additions to .js files.
Related NHI Mgmt Group resources
tj-actions Supply Chain Attack 2025 · Shai-Hulud Campaign · CI/CD Pipeline Identity Security Guide · Secrets Management Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Developer tokens and CI/CD secrets are now a primary target in supply chain attacks. We help teams inventory tokens, move to fine-grained and short-lived credentials and protect pipeline secrets. See our NHI and AI agent security training.
References
- Checkmarx: Surprise, When Dependabot Contributes Malicious Code (27 September 2023)
- BleepingComputer: GitHub repos bombarded by info-stealing commits masked as Dependabot (27 September 2023)
- SecurityWeek: Stolen GitHub Credentials Used to Push Fake Dependabot Commits (27 September 2023)