Illustration of a lock icon over a GitHub logo, symbolizing a cybersecurity threat to GitHub repositories and open-source projects.
Uncategorized

GhostAction Unleashed: Thousands of GitHub Repositories Compromised in Massive Credential Theft Campaign

Share
Share
Pinterest Hidden

The Shadowy Reach of GhostAction: A GitHub Supply Chain Crisis

The digital landscape is abuzz with urgent warnings as cybersecurity researchers unveil the alarming scale of an ongoing credential-theft campaign. Dubbed ‘GhostAction,’ this sophisticated attack has infiltrated tens of thousands of GitHub repositories, leveraging compromised open-source maintainer accounts to plant insidious workflows designed to pilfer sensitive data.

First surfacing in September 2025, GhostAction has resurfaced with renewed vigor, demonstrating a chilling efficiency in its latest wave of attacks. Reports indicate that over 500 GitHub accounts have been implicated, committing malicious workflows to an astounding number of repositories since October 7, 2026. The campaign’s previous iteration impacted 817 repositories across 327 GitHub users, leading to the exfiltration of 3,325 secrets, including critical PyPI, npm, and DockerHub tokens.

High-Profile Maintainers Fall Victim

The recent breaches highlight the vulnerability of even prominent open-source projects. In a swift and targeted operation, attackers compromised the accounts of two highly respected maintainers:

  • Takashi Kitao: Author of the popular 18,400-star game engine, pyxel. His account was used to push a malicious workflow to 27 repositories within a single hour on October 9, 2026.
  • Henry Wu (henrywoo): Original creator of Uber’s athenadriver. Just eight hours after Kitao’s compromise, Wu’s account was exploited to inject the same malicious workflow into 318 repositories in a mere 16-minute window.

Anatomy of the Attack: The Malicious Workflow

The core of the GhostAction campaign lies in its cleverly disguised GitHub Actions workflows. These workflows, typically named “Security Audit” (security-audit.yml) or “GitHub Actions Security” (github_actions_security.yml), are far from benign. Their primary function is to exfiltrate a treasure trove of sensitive data to a hard-coded IP address (193.32.204[.]199) over plain HTTP.

The stolen data is comprehensive, encompassing:

  • Repository’s named GitHub Actions secrets, including CI/CD secrets.
  • Cloud, AI, and SaaS credentials found in the working tree and the entire Git history.
  • Specific keys such as AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens.

The Attack Chain: A Step-by-Step Breakdown

The sophisticated attack unfolds in a meticulously planned sequence:

  1. Credential Acquisition: The attacker first obtains a maintainer’s GitHub credentials, most likely through leaked Personal Access Tokens (PATs) from infostealer logs or credential dumps.
  2. Reconnaissance: The repository’s workflow files are scanned for existing secrets, identifying potential targets for exfiltration.
  3. Malicious Injection: A workflow, masquerading as a legitimate security audit, is injected into the default branch under the victim’s own identity.
  4. Data Exfiltration: The embedded payload activates, extracting the identified data and transmitting it to an attacker-controlled endpoint via curl.

StepSecurity detailed the ‘Audit’ step’s four critical actions:

  • Appending named secrets discovered during reconnaissance.
  • Scanning the working tree for 13 specific credential patterns (AWS keys, AI services, source control, SaaS, and cloud API keys).
  • Checking the entire Git history for these same patterns to harvest inadvertently committed and deleted credentials.
  • Pairing AWS access key IDs with their corresponding secret access keys.

Beyond Credentials: The Threat of Cryptominers

While credential theft is the primary objective, GhostAction’s versatility extends to other malicious activities. GitGuardian reported that between August 31 and September 30, 2026, the campaign pushed malicious workflows to 772 public repositories, targeting 2,577 secrets including SSH private keys, Azure credentials, DockerHub, GHCR, database, AWS, FTP, Google Cloud, Firebase credentials, GitHub tokens, and various bot tokens (Telegram, Slack, Discord), alongside keys for Cloudflare, npm, PyPI, and AI providers.

In a particularly concerning incident on August 30, 2026, threat actors altered the “kuafuai/DevOpsGPT” repository to embed an XMRig cryptocurrency miner within the project’s Docker image. While no malicious package releases using compromised publishing credentials have been observed yet, the potential for further supply chain poisoning remains high.

Protecting Your Projects: Urgent Security Recommendations

Given the widespread nature and severity of the GhostAction campaign, immediate action is crucial for all GitHub users and maintainers.

Immediate Steps for Developers:

  1. Audit Your Repositories: Scrutinize your repositories for the presence of “security-audit.yml” or “github_actions_security.yml” workflows, particularly any committed since August 31, 2026.
  2. Assume Compromise: If these malicious workflows are found, immediately assume your account and associated credentials have been compromised.
  3. Revoke Credentials: Revoke any compromised GitHub credentials (e.g., Personal Access Tokens).
  4. Rotate Secrets: Rotate all credentials that may have been exposed, including CI/CD secrets, cloud API keys, and any other sensitive data.
  5. Delete Malicious Workflows: Remove the malicious workflow files from all branches of your repositories.
  6. Check Forks: Inspect all forks of infected repositories, as they can also inherit and trigger credential harvesting.

The Hidden Dangers of Forks and Private Repositories:

The threat extends beyond the immediate repository. As Socket warns, “The 279 forks in the henrywoo namespace each carry the workflow file. If Actions are enabled, subsequent pushes can trigger credential harvesting.” Downstream forks are equally at risk if they inherit the malicious workflow, either upon creation or through synchronization with the affected upstream repository.

Private repositories and downstream mirrors are particularly exposed, as they are often the locations where committed credentials are most likely to be found. The attackers, by mapping reachable execution contexts, gain valuable insights into potential targets, regardless of whether credentials are immediately found.

This ongoing campaign underscores the critical importance of robust supply chain security practices and vigilant monitoring in the open-source ecosystem. Stay informed, stay secure.


For more details, visit our website.

Source: Link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *