AI-Driven Actor Ran Six Waves of GitHub pull_request_target Abuse

A single attacker used AI automation to run six distinct waves of malicious pull_request_target exploits on GitHub starting March 11, 2026, weeks before public disclosure. This campaign produced over 500 malicious pull requests and compromised at least two npm packages. The attacker evolved payloads from simple scripts to AI-generated, language-aware code, increasing stealth and adaptability. This reveals that the threat is persistent and scalable, not a one-off burst. Any repository exposing secrets or privileged workflows to untrusted pull requests via pull_request_target is at risk of supply-chain compromise, including poisoned packages and stolen tokens. Standard remediation steps miss the persistence of published artifacts and the rapid retry capability enabled by AI tooling. This campaign demands urgent operational response to remove secrets and convert sensitive workflows to trusted contexts.

Part of the PlainSec briefing for 2026-04-06

Sources