prt-scan is a multi-wave software supply chain threat activity cluster focused on exploiting GitHub Actions workflows that use the pull_request_target trigger in unsafe ways. The actor conducted large-scale automated pull request operations beginning in March 2026, using multiple GitHub accounts to identify vulnerable repositories, fork them, modify CI-executed files, and submit malicious pull requests designed to run in the security context of the target repository. The campaign targeted both prominent open-source organizations and smaller hobbyist projects, with observed injections tailored to Python, Node.js, Go, Rust, and GitHub Actions environments. The actor’s primary objective was theft of CI/CD secrets and related credentials. Observed tradecraft included exfiltrating GitHub workflow tokens, enumerating repository and organization secrets metadata, probing cloud metadata services, and attempting to expose additional secrets through workflow logs and pull request comments. When package publishing credentials were discovered, the actor attempted follow-on supply chain abuse by publishing trojanized package versions. Confirmed downstream impact included compromise of npm packages associated with at least two projects, and a later intrusion affecting multiple AsyncAPI packages after theft of an npm publish token through the same pull_request_target abuse pattern. Across the campaign, the actor opened well over 500 malicious pull requests over six waves and evolved from crude shell-based payloads to AI-assisted, repository-aware wrappers adapted to the target language and build environment. Payload logic commonly followed staged exfiltration and reconnaissance flows, with attempts to dump environment variables, inspect workflow configuration, trigger additional workflows, and bypass label- or approval-based controls. Despite the scale of activity, the operator has been assessed as relatively low sophistication because many payloads misunderstood GitHub permission boundaries and several attack stages were ineffective in typical repository configurations. In successful cases, prt-scan demonstrated capabilities spanning initial access, reconnaissance, credential theft, exfiltration, persistence, and post-exploitation. In the AsyncAPI-related package compromise, malicious runtime code fetched additional staged payloads, established host persistence across major operating systems, and enabled remote shell execution. Code associated with that later payload also contained disabled functionality for credential harvesting, propagation, evasion, mutation, and poisoning of AI-development tooling. Attribution beyond the activity cluster itself remains inconclusive; branding found in later-stage malware has not been established as reliable evidence of actor identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated in the content with GitHub Actions secret-theft attacks using pull_request_target abuse, PR flooding, and dead-drop exfiltration.
Automated supply-chain campaign exploiting GitHub pull_request_target workflow misconfigurations at scale via malicious pull requests, stealing CI secrets/tokens, probing cloud metadata, and publishing malicious npm package versions when NPM_TOKEN was found.
AI-assisted supply chain campaign exploiting GitHub pull_request_target workflow misconfigurations at scale, opening over 500 malicious pull requests, stealing workflow credentials and secrets, probing cloud metadata, and successfully compromising at least two npm packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.