Cybersecurity researchers have uncovered alarming new details regarding an ongoing credential-theft campaign known as GhostAction, which has successfully compromised high-profile open-source maintainer accounts to propagate malicious workflows across tens of thousands of software repositories. The sophisticated supply chain attacks highlight persistent vulnerabilities in developer infrastructure, casting a wide net that threatens software integrity, continuous integration pipelines, and sensitive cloud credentials across the global developer ecosystem.

According to recent advisories from security firms StepSecurity and Socket, the sophisticated attack vector involves hijacking established developer accounts to inject automated surveillance and exfiltration scripts. The most recent wave of activity underscores how threat actors continue to leverage trusted community figures to bypass traditional security perimeters, weaponizing automated CI/CD pipelines to harvest critical secrets before development teams can detect the breach.

High-Profile Maintainer Accounts Weaponized in Rapid Succession

The latest phase of the campaign demonstrated a high degree of operational coordination and speed. Security telemetry revealed that attackers exploited the trusted account of Takashi Kitao, the esteemed author of the popular 18,400-star game engine Pyxel. Using Kitao’s compromised credentials, the malicious actors pushed a fraudulent workflow into 27 repositories starting precisely at 13:20 UTC.

Just eight hours later, the threat actors struck again. This time, they seized control of the account belonging to Henry Wu (known as henrywoo), the original author of Uber’s widely utilized athenadriver library. In a compressed 16-minute window between 21:10 and 21:26 UTC, Wu’s account was leveraged to push the exact same malicious workflow to a staggering 318 repositories.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

The scale of the operation expanded rapidly as downstream systems processed the updates. Socket reported that by October 9, 2026, investigations had identified more than 500 distinct GitHub accounts that had committed the malicious workflow to tens of thousands of repositories since October 7, 2026. This massive propagation relies heavily on automated inheritance, wherein downstream forks and dependent projects automatically pull or synchronize with infected upstream codebases, thereby amplifying the reach of the initial account compromise.

Tracing the Origins and Evolution of GhostAction

The ongoing incidents form part of a broader, well-documented supply chain threat campaign designated as GhostAction. The campaign first came to light in September 2025, when researchers exposed an extensive effort that ultimately impacted 817 repositories across 327 GitHub users. That initial wave resulted in the successful exfiltration of 3,325 sensitive secrets, including critical publishing tokens for major ecosystems like PyPI, npm, and DockerHub, all harvested through compromised developer accounts.

Subsequent investigations by GitGuardian revealed that between August 31 and September 30, 2026, the GhostAction campaign had already pushed its malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations. These continuous waves of deployment indicate that the threat actors behind GhostAction maintain an active, persistent infrastructure capable of repeatedly identifying, targeting, and compromising high-value maintainer credentials across the software development landscape.

In at least one concerning instance observed on August 30, 2026, the threat actors escalated their activities beyond simple credential harvesting. Investigators found that the attackers had altered the "kuafuai/DevOpsGPT" repository to embed an XMRig cryptocurrency miner directly into the project’s official Docker image. Although cybersecurity analysts note that no malicious package releases have been published using compromised publishing credentials as of yet, the potential for arbitrary code execution within trusted software supply chains remains an alarming reality.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Mechanics of the Malicious Workflow and Data Harvesting

The malicious payloads deployed in this campaign are disguised to blend into normal development operations. Researchers identified that the injected workflows are typically named "Security Audit" (security-audit.yml) or "GitHub Actions Security" (github_actions_security.yml). Designed to evade casual inspection, these scripts execute surreptitiously to harvest and exfiltrate sensitive data over plain HTTP to a hard-coded external IP address located at 193.32.204[.]199.

According to technical breakdowns provided by StepSecurity, the attack chain is triggered automatically upon a workflow_dispatch event or via an unfiltered push across any branch or tag. The workflow checks out the repository with an expansive fetch-depth: 0 parameter, ensuring that the entire historical record of the codebase is accessible to the script. It then executes a streamlined audit step designed to sweep through the working tree and the complete Git history.

The scope of data targeted by these workflows is extraordinarily broad. The injected scripts are configured to vacuum up named GitHub Actions secrets, CI/CD configuration tokens, and a vast array of cloud, AI, and SaaS credentials present within the project environment. Among the 2,577 specific secrets targeted by the latest iterations of GhostAction are AWS access keys and secret keys, Anthropic, OpenAI, and OpenRouter API keys, GitHub and GitLab tokens, SSH private keys, Azure credentials, database connection strings, DockerHub and GitHub Container Registry credentials, FTP credentials, Google Cloud and Firebase keys, and various bot tokens for platforms like Telegram, Slack, and Discord, alongside credentials for Cloudflare, npm, and PyPI.

Furthermore, security experts have noted a particularly insidious aspect of the campaign’s data collection methodology: even in repositories where no hardcoded credentials or environment secrets are discovered, every execution of the malicious workflow returns a unique repository identifier to the attackers. This ensures that the threat actors maintain an up-to-date, comprehensive map of reachable execution contexts, independent of whether an individual compromise yields immediate financial or operational secrets.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Mitigation Strategies and Impact on Downstream Forks

The implications of the GhostAction campaign extend far beyond the primary repositories owned by compromised maintainers. Industry analysts have emphasized the severe risk posed by downstream forks and mirrors, which often inherit GitHub Actions workflows automatically upon creation or during routine synchronization with infected upstream sources.

Socket warned that forks within specific namespaces, such as the 279 forks found in the henrywoo namespace, carry the malicious workflow file natively. If GitHub Actions are enabled on these forks, subsequent code pushes can inadvertently trigger credential harvesting operations. Private forks and enterprise mirrors are identified as being particularly vulnerable and exposed, because private repositories are precisely where sensitive production credentials, corporate API keys, and proprietary secrets are most frequently stored.

In response to these developments, cybersecurity authorities and platform maintainers strongly advise developers and organizations to immediately audit their repositories. Development teams are urged to inspect their codebases for the presence of either of the two identified malicious GitHub workflow files since August 31, 2026.

Any organization finding these files within their repositories must assume immediate compromise. Recommended remediation steps include revoking all compromised GitHub credentials, aggressively rotating associated cloud, SaaS, and API keys, completely removing the malicious workflow files from all branches, and thoroughly inspecting any forks or dependent repositories that may have inherited the malicious code. As the GhostAction campaign continues to adapt and strike across open-source ecosystems, vigilance and rapid incident response remain the primary defense for maintaining software supply chain integrity.

Leave a Reply

Your email address will not be published. Required fields are marked *