
GhostAction Campaign Plants Credential-Stealing GitHub Actions Workflows in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed an ongoing credential-theft campaign attributed to GhostAction that compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
Compromised Maintainer Accounts Push Malicious Workflow
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC. Eight hours later, the account of Henry Wu (henrywoo), the original author of Uber's athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window between 21:10 and 21:26 UTC.
As of October 9, 2026, Socket said it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026. The activity has been attributed to GhostAction, a massive supply chain attack campaign that first came to light in September 2025.
Workflow Exfiltrates Secrets to Hard-Coded IP
Both accounts pushed a workflow named Security Audit (security-audit.yml) or GitHub Actions Security (github_actions_security.yml), designed to exfiltrate sensitive data to a hard-coded IP address (193.32.204.199) over plain HTTP. The captured data contains the repository's named GitHub Actions secrets, including CI/CD secrets, and cloud, AI, and SaaS credentials present in the working tree and the entire git history, such as AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens.
The attack chain begins with the attacker obtaining a maintainer's GitHub credentials, most likely a leaked personal access token from infostealer logs or credential dumps. The repository's workflow files are scanned for secrets as part of reconnaissance. A workflow masquerading as a security audit is then injected into the default branch under the victim's own identity. The embedded payload extracts the data and sends it to an attacker-controlled endpoint via curl.
Scope and Recommendations
GitGuardian reported that the GhostAction campaign pushed the malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026. The injected workflows target 2,577 secrets, including SSH private keys, Azure credentials, DockerHub and GHCR container registry credentials, database credentials, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, Telegram, Slack, and Discord bot tokens, and keys associated with Cloudflare, npm, PyPI, and AI providers.
In at least one case observed on August 30, 2026, the threat actors altered the kuafuai/DevOpsGPT repository to embed an XMRig cryptocurrency miner in the project's Docker image. As of writing, no malicious package releases have been published using compromised publishing credentials.
Developers are advised to check their repositories for either of the two GitHub workflows since August 31, 2026, and assume compromise if present. It is recommended to revoke the compromised GitHub credential, rotate credentials, delete the malicious workflow from all branches, and check forks of the infected repositories. Socket noted that the 279 forks in the henrywoo namespace each carry the workflow file, and that private forks and downstream mirrors are the most exposed because private repositories are where committed credentials are actually found.
Sources: The Hacker News
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.