What Is the GhostAction Attack?
GhostAction is a supply-chain attack campaign that hijacks trusted GitHub maintainer accounts and uses them to plant a credential-stealing workflow into open-source repositories. The malicious file is disguised as a routine “security audit,” but its only job is to harvest secrets: GitHub Actions tokens, AWS keys, AI API keys, and anything else it can find in the repository and its full git history. The stolen data is sent to a single attacker-controlled IP address over plain HTTP.
On October 8, 2026, the campaign surged again. Two compromised maintainer accounts pushed the payload into 346 repositories in minutes. Socket later reported that more than 500 GitHub accounts had committed the malicious workflow to tens of thousands of repositories since October 7. This is one of the largest GitHub supply-chain incidents of the year, and it shows how the theft of one developer’s login can cascade into an industry-wide problem.
The October 2026 Wave: What Happened
The two compromised accounts
The burst was documented by both Socket and StepSecurity. The attacker used the GitHub accounts of two well-known open-source maintainers:
- kitao, the account of Takashi Kitao, author of the pyxel game engine with roughly 18,400 stars. Starting around 13:20 UTC on October 8, the attacker pushed the malicious workflow into 27 repositories in about four minutes.
- henrywoo, the account of Henry Wu, the original author of Uber’s athenadriver. In a 16-minute window between 21:10 and 21:26 UTC, the same workflow was pushed into 318 repositories, including the organization-owned uber/athenadriver repository itself, where Wu still had write access.
The inclusion of decade-dormant repositories alongside active ones suggests the attacker was running an automated sweep rather than picking targets by hand.
How the malicious workflow works
The payload is a single file, .github/workflows/security-audit.yml (or github_actions_security.yml), committed with the innocuous message “Add security audit workflow.” It performs no security function at all. Instead, once it runs, it:
- Collects the repository’s named GitHub Actions secrets, including CI/CD tokens.
- Scans the working directory and the entire git history for credential patterns: AWS access keys, Anthropic API keys, OpenAI project keys, OpenRouter keys, GitHub and GitLab tokens, Google/Firebase credentials, Slack tokens, and SendGrid keys.
- Grabs two lines of context around AWS key matches to maximize the damage.
- Bundles everything into one cleartext HTTP POST to
193.32.204.199, the same hardcoded IP address the campaign has used before.
The history sweep is the nasty part. The workflow pulls the full repository history (fetch-depth: 0) and mines it with tools like git log -p --all, so credentials you committed and deleted years ago are exposed all over again. Rotating only your current secrets is not enough.
The scale keeps growing
Socket’s October 9 update reported that more than 500 GitHub accounts had committed the malicious workflow to tens of thousands of repositories since October 7, including several organization-owned ones reached through compromised contributors. StepSecurity counted 378 repositories still hosting the live payload and 182 showing signs of the history-mining step. Socket confirmed that kitao/pyxel was a clear-cut case of successful exfiltration: publishing credentials were captured by a completed run.
There is one piece of good news. StepSecurity noted that at least one repository with mandatory workflow approval turned on blocked the exfiltration. And as of publication, researchers had not seen any malicious package releases built from the stolen credentials. That may only be a matter of time.
This Is Not the First GhostAction Wave
The campaign has a history, and it is worth knowing:
- September 2025: GitGuardian first exposed and named the campaign. The initial wave compromised 817 public repositories across 327 GitHub users and exfiltrated at least 3,325 secrets, including PyPI, npm, and DockerHub tokens.
- Summer 2026: researchers observed a fresh spike in malicious commits using the same technique.
- October 2026: the current wave, expanded from CI/CD secrets to full cloud-credential theft.
GitGuardian also notes that this injection technique was later reused during the Shai-Hulud campaigns, the same family of attacks behind the TensorLake npm compromise covered here earlier this week. Malicious workflow injection has become a repeatable playbook for supply-chain attackers.
How the Attackers Get In
According to the research, the attacker most likely obtained the maintainers’ GitHub credentials through leaked personal access tokens found in infostealer logs or credential dumps. In other words, a token that sat in a compromised log somewhere months ago can be replayed to take over a respected maintainer’s account today.
This is the pattern to watch for in 2026: attackers are not always finding new vulnerabilities. They are harvesting old credentials from breach data and using them against high-trust targets. GitHub has become a proving ground for it, with attackers hiding crypto miners in public repos earlier this month as well.
What to Do Right Now
1. Check your repositories for the payload
Look at .github/workflows/ in every repository you maintain. Search for files named security-audit.yml or github_actions_security.yml, and review recent commits with messages like “Add security audit workflow” or “Update security audit workflow” that you did not author.
2. Rotate everything, not just current secrets
Because the attack mines full git history, rotate any credential that ever appeared in your repository history: AWS keys, API tokens, CI/CD secrets, and signing keys. Then use GitHub’s secret-scanning push protection to stop this from recurring.
3. Require workflow approval
Turn on required approval for all outside contributors, and consider requiring it for first-time contributors too. This single setting blocked exfiltration in at least one targeted repository.
4. Harden the accounts themselves
Switch to fine-grained personal access tokens with the smallest possible scope, enable 2FA (preferably passkeys), and monitor commit activity on your accounts. If you maintain a popular project, free security tooling like the new OSS vulnerability scanners can help you stay ahead of exactly this kind of threat.
Frequently Asked Questions
What is the GhostAction attack?
GhostAction is a supply-chain campaign in which attackers take over GitHub maintainer accounts and commit a fake “security audit” workflow that steals CI/CD secrets and cloud credentials, then sends them to an attacker-controlled server. The campaign has been active since September 2025 and surged again in October 2026.
Which repositories were affected?
The October 8, 2026 burst hit 346 repositories through two compromised accounts, including the 18,400-star pyxel game engine and Uber’s athenadriver. Socket later reported the workflow had been committed to tens of thousands of repositories since October 7, including organization-owned ones.
What data does the malicious workflow steal?
It steals named GitHub Actions secrets and scans the working tree plus the full git history for AWS keys, Anthropic, OpenAI, and OpenRouter API keys, GitHub and GitLab tokens, Google/Firebase credentials, Slack tokens, and SendGrid keys.
Can the attack still reach me if my credentials are only in old commits?
Yes. The workflow mines the entire git history, so keys you committed and deleted years ago are still exposed. Rotating only current secrets is not enough after a compromise.
How do I know if my repository was compromised?
Check .github/workflows/ for unfamiliar files such as security-audit.yml, audit your recent commit history for commits you did not make, and review Actions run logs for outbound requests to unfamiliar IPs like 193.32.204.199.
