Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign

A coordinated supply chain campaign dubbed "prt-scan" involved a single attacker controlling six GitHub accounts to exploit the pull_request_target GitHub Actions trigger. The campaign represents a follow-up to the earlier hackerbot-claw campaign, targeting CI/CD workflows with AI-powered attack methods.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Supply chain developers using prt-scan and similar CI/CD systems exploiting pull_request_target
Ecosystems
Attack vectors
Threat actor
Affected entities
  • prt-scanTarget of supply chain campaign exploiting pull_request_target GitHub Actions feature

A sophisticated supply chain campaign targeting CI/CD infrastructure has been identified by Wiz researchers. The attack, named the "prt-scan" campaign, involved a single attacker operating six separate GitHub accounts to exploit the pull_request_target GitHub Actions trigger—a known vector for code injection in CI/CD pipelines.

This campaign represents a continuation of threats earlier demonstrated by the "hackerbot-claw" campaign, confirming that adversaries are actively developing repeatable tactics against GitHub Actions workflows. The pull_request_target trigger allows pull request code to run in the context of the base branch, creating a critical security boundary issue when combined with malicious inputs.

Wiz researchers traced the attacker's activity back three weeks before public detection, indicating the campaign had been operating covertly while establishing infrastructure across multiple accounts. The use of multiple accounts suggests sophistication in obfuscating attack patterns and distributing malicious actions across the supply chain.

The campaign highlights the ongoing threat to development infrastructure and the need for organizations to audit pull request handling in their CI/CD pipelines.

Remediation

  • Audit and restrict use of pull_request_target in GitHub Actions workflows; prefer pull_request trigger with explicit secret management
  • Implement mandatory code review and approval gates for all pull requests before CI/CD execution
  • Monitor GitHub account activity for suspicious patterns, including mass account creation and coordinated pull request activity
  • Apply the principle of least privilege to GitHub Actions secrets and environment variables
  • Use tools to detect and alert on unusual CI/CD pipeline modifications or account behavior

Sources

  1. Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign · Wiz

Cite this entry

"Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed April 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign-1s2s4f

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit