Skip to content

TechToRev

Menu
  • Home
  • Contact
Menu
GhostAction credential-stealing GitHub Actions attack illustration

GhostAction Returns: How Attackers Turned GitHub Actions Into a Credential-Stealing Machine

Posted on October 10, 2026 by saudshoukat199@gmail.com

What Is the GhostAction Attack?

GhostAction is a supply-chain attack campaign that hijacks trusted GitHub maintainer accounts and uses them to plant a credential-stealing workflow into open-source repositories. The malicious file is disguised as a routine “security audit,” but its only job is to harvest secrets: GitHub Actions tokens, AWS keys, AI API keys, and anything else it can find in the repository and its full git history. The stolen data is sent to a single attacker-controlled IP address over plain HTTP.

On October 8, 2026, the campaign surged again. Two compromised maintainer accounts pushed the payload into 346 repositories in minutes. Socket later reported that more than 500 GitHub accounts had committed the malicious workflow to tens of thousands of repositories since October 7. This is one of the largest GitHub supply-chain incidents of the year, and it shows how the theft of one developer’s login can cascade into an industry-wide problem.

The October 2026 Wave: What Happened

The two compromised accounts

The burst was documented by both Socket and StepSecurity. The attacker used the GitHub accounts of two well-known open-source maintainers:

  • kitao, the account of Takashi Kitao, author of the pyxel game engine with roughly 18,400 stars. Starting around 13:20 UTC on October 8, the attacker pushed the malicious workflow into 27 repositories in about four minutes.
  • henrywoo, the account of Henry Wu, the original author of Uber’s athenadriver. In a 16-minute window between 21:10 and 21:26 UTC, the same workflow was pushed into 318 repositories, including the organization-owned uber/athenadriver repository itself, where Wu still had write access.

The inclusion of decade-dormant repositories alongside active ones suggests the attacker was running an automated sweep rather than picking targets by hand.

How the malicious workflow works

The payload is a single file, .github/workflows/security-audit.yml (or github_actions_security.yml), committed with the innocuous message “Add security audit workflow.” It performs no security function at all. Instead, once it runs, it:

  • Collects the repository’s named GitHub Actions secrets, including CI/CD tokens.
  • Scans the working directory and the entire git history for credential patterns: AWS access keys, Anthropic API keys, OpenAI project keys, OpenRouter keys, GitHub and GitLab tokens, Google/Firebase credentials, Slack tokens, and SendGrid keys.
  • Grabs two lines of context around AWS key matches to maximize the damage.
  • Bundles everything into one cleartext HTTP POST to 193.32.204.199, the same hardcoded IP address the campaign has used before.

The history sweep is the nasty part. The workflow pulls the full repository history (fetch-depth: 0) and mines it with tools like git log -p --all, so credentials you committed and deleted years ago are exposed all over again. Rotating only your current secrets is not enough.

The scale keeps growing

Socket’s October 9 update reported that more than 500 GitHub accounts had committed the malicious workflow to tens of thousands of repositories since October 7, including several organization-owned ones reached through compromised contributors. StepSecurity counted 378 repositories still hosting the live payload and 182 showing signs of the history-mining step. Socket confirmed that kitao/pyxel was a clear-cut case of successful exfiltration: publishing credentials were captured by a completed run.

There is one piece of good news. StepSecurity noted that at least one repository with mandatory workflow approval turned on blocked the exfiltration. And as of publication, researchers had not seen any malicious package releases built from the stolen credentials. That may only be a matter of time.

This Is Not the First GhostAction Wave

The campaign has a history, and it is worth knowing:

  • September 2025: GitGuardian first exposed and named the campaign. The initial wave compromised 817 public repositories across 327 GitHub users and exfiltrated at least 3,325 secrets, including PyPI, npm, and DockerHub tokens.
  • Summer 2026: researchers observed a fresh spike in malicious commits using the same technique.
  • October 2026: the current wave, expanded from CI/CD secrets to full cloud-credential theft.

GitGuardian also notes that this injection technique was later reused during the Shai-Hulud campaigns, the same family of attacks behind the TensorLake npm compromise covered here earlier this week. Malicious workflow injection has become a repeatable playbook for supply-chain attackers.

How the Attackers Get In

According to the research, the attacker most likely obtained the maintainers’ GitHub credentials through leaked personal access tokens found in infostealer logs or credential dumps. In other words, a token that sat in a compromised log somewhere months ago can be replayed to take over a respected maintainer’s account today.

This is the pattern to watch for in 2026: attackers are not always finding new vulnerabilities. They are harvesting old credentials from breach data and using them against high-trust targets. GitHub has become a proving ground for it, with attackers hiding crypto miners in public repos earlier this month as well.

What to Do Right Now

1. Check your repositories for the payload

Look at .github/workflows/ in every repository you maintain. Search for files named security-audit.yml or github_actions_security.yml, and review recent commits with messages like “Add security audit workflow” or “Update security audit workflow” that you did not author.

2. Rotate everything, not just current secrets

Because the attack mines full git history, rotate any credential that ever appeared in your repository history: AWS keys, API tokens, CI/CD secrets, and signing keys. Then use GitHub’s secret-scanning push protection to stop this from recurring.

3. Require workflow approval

Turn on required approval for all outside contributors, and consider requiring it for first-time contributors too. This single setting blocked exfiltration in at least one targeted repository.

4. Harden the accounts themselves

Switch to fine-grained personal access tokens with the smallest possible scope, enable 2FA (preferably passkeys), and monitor commit activity on your accounts. If you maintain a popular project, free security tooling like the new OSS vulnerability scanners can help you stay ahead of exactly this kind of threat.

Frequently Asked Questions

What is the GhostAction attack?

GhostAction is a supply-chain campaign in which attackers take over GitHub maintainer accounts and commit a fake “security audit” workflow that steals CI/CD secrets and cloud credentials, then sends them to an attacker-controlled server. The campaign has been active since September 2025 and surged again in October 2026.

Which repositories were affected?

The October 8, 2026 burst hit 346 repositories through two compromised accounts, including the 18,400-star pyxel game engine and Uber’s athenadriver. Socket later reported the workflow had been committed to tens of thousands of repositories since October 7, including organization-owned ones.

What data does the malicious workflow steal?

It steals named GitHub Actions secrets and scans the working tree plus the full git history for AWS keys, Anthropic, OpenAI, and OpenRouter API keys, GitHub and GitLab tokens, Google/Firebase credentials, Slack tokens, and SendGrid keys.

Can the attack still reach me if my credentials are only in old commits?

Yes. The workflow mines the entire git history, so keys you committed and deleted years ago are still exposed. Rotating only current secrets is not enough after a compromise.

How do I know if my repository was compromised?

Check .github/workflows/ for unfamiliar files such as security-audit.yml, audit your recent commit history for commits you did not make, and review Actions run logs for outbound requests to unfamiliar IPs like 193.32.204.199.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • GhostAction credential-stealing GitHub Actions attack illustration
    GhostAction Returns: How Attackers Turned GitHub Actions Into a Credential-Stealing Machine
    by saudshoukat199@gmail.com
    October 10, 2026
  • Illustration of a messaging chat window with a malicious link and a digital key being stolen, representing the Telegram Desktop one-click account takeover vulnerability
    Telegram Desktop One-Click Account Takeover (CVE-2026-107181): What Happened and How to Stay Safe
    by saudshoukat199@gmail.com
    October 10, 2026
  • Midnight Mimosa malware illustration: smartphone with circuit traces in shipping box
    Midnight Mimosa Malware: Why Thousands of Budget Android Phones Arrived Hacked Out of the Box
    by saudshoukat199@gmail.com
    October 10, 2026
  • Cracked glowing security shield in a dark server room illustrating the AhsayCBS zero-day vulnerability compromising backup servers
    AhsayCBS Zero-Day Exploited in the Wild: Attackers Turn Backup Servers Into Crypto Miners
    by saudshoukat199@gmail.com
    October 10, 2026
  • Illustration of a cybersecurity shield over a global network as the FBI seizes Flax Typhoon's MicroScan and FishHub hacking tools
    FBI Seizes Flax Typhoon Hacking Tools MicroScan and FishHub: What Happened and What to Do
    by saudshoukat199@gmail.com
    October 10, 2026
© 2026 TechToRev | Powered by Superbs Personal Blog theme