Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign
A coordinated supply chain campaign dubbed "prt-scan" involved a single attacker controlling six GitHub accounts to exploit the pull_request_target GitHub Actions trigger. The campaign represents a follow-up to the earlier hackerbot-claw campaign, targeting CI/CD workflows with AI-powered attack methods.
- Disclosed
- Last updated
- Blast radius
- Supply chain developers using prt-scan and similar CI/CD systems exploiting pull_request_target
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- prt-scanTarget of supply chain campaign exploiting pull_request_target GitHub Actions feature
A sophisticated supply chain campaign targeting CI/CD infrastructure has been identified by Wiz researchers. The attack, named the "prt-scan" campaign, involved a single attacker operating six separate GitHub accounts to exploit the pull_request_target GitHub Actions trigger—a known vector for code injection in CI/CD pipelines.
This campaign represents a continuation of threats earlier demonstrated by the "hackerbot-claw" campaign, confirming that adversaries are actively developing repeatable tactics against GitHub Actions workflows. The pull_request_target trigger allows pull request code to run in the context of the base branch, creating a critical security boundary issue when combined with malicious inputs.
Wiz researchers traced the attacker's activity back three weeks before public detection, indicating the campaign had been operating covertly while establishing infrastructure across multiple accounts. The use of multiple accounts suggests sophistication in obfuscating attack patterns and distributing malicious actions across the supply chain.
The campaign highlights the ongoing threat to development infrastructure and the need for organizations to audit pull request handling in their CI/CD pipelines.
Remediation
- Audit and restrict use of pull_request_target in GitHub Actions workflows; prefer pull_request trigger with explicit secret management
- Implement mandatory code review and approval gates for all pull requests before CI/CD execution
- Monitor GitHub account activity for suspicious patterns, including mass account creation and coordinated pull request activity
- Apply the principle of least privilege to GitHub Actions secrets and environment variables
- Use tools to detect and alert on unusual CI/CD pipeline modifications or account behavior
Sources
Cite this entry
"Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed April 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/six-accounts-one-actor-inside-the-prt-scan-supply-chain-campaign-1s2s4f
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/gi-assets-basic (npm)
A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g6-extension-3d (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in gantt-for-react (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-sdk-app (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit