VMTech
Discuss a project →

GhostAction Workflows Spread Credential Theft Across GitHub Repositories

GhostAction Workflows Spread Credential Theft Across GitHub Repositories

Researchers have reported a renewed GhostAction supply-chain campaign in which compromised GitHub maintainer accounts were used to inject credential-stealing GitHub Actions workflows into hundreds of repositories. StepSecurity said the account of Takashi Kitao, author of the pyxel game engine with 18,400 stars, pushed a malicious workflow to 27 repositories from 13:20 UTC. Eight hours later, Henry Wu’s henrywoo account pushed the same workflow to 318 repositories in a 16-minute period between 21:10 and 21:26 UTC.

Socket said that, as of October 9, 2026, it had identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7. The activity is attributed to GhostAction, a large-scale supply-chain attack campaign first disclosed in September 2025.

Workflows impersonate security checks

The injected files are named security-audit.yml, presented as “Security Audit,” or github_actions_security.yml, presented as “GitHub Actions Security.” Both are designed to collect sensitive data and send it to the hard-coded address 193.32.204[.]199 over unencrypted HTTP.

The workflow triggers through workflow_dispatch and an unfiltered push event, meaning a push to any branch or tag can activate it. It checks out the repository with fetch-depth: 0, making the full Git history available, then executes a single Audit step.

Secrets in files, Actions settings and history are at risk

StepSecurity said the payload appends repository secrets identified during reconnaissance, searches the working tree for 13 credential patterns and searches the full Git history for the same patterns. It also pairs AWS access key IDs with matching secret access keys. The targeted material includes CI/CD secrets, AWS credentials, Anthropic, OpenAI and OpenRouter API keys, plus GitHub and GitLab tokens.

GitGuardian had already identified a related GhostAction wave affecting 772 public repositories across 373 GitHub users and organizations between August 31 and September 30, 2026. Those workflows targeted 2,577 secrets, including SSH private keys, Azure, Google Cloud and Firebase credentials, registry credentials, database credentials, FTP credentials, chat-platform bot tokens, and keys for Cloudflare, npm, PyPI and AI providers.

In the broader activity, 817 repositories belonging to 327 GitHub users were affected and 3,325 secrets were exfiltrated through compromised developer accounts. Researchers also observed an August 30 alteration of the kuafuai/DevOpsGPT repository that embedded an XMRig cryptocurrency miner in the project’s Docker image. No malicious package releases using compromised publishing credentials had been published at the time of reporting.

Forks can preserve the exposure

The risk does not stop with the initially altered repositories. Socket noted that all 279 forks in the henrywoo namespace carry the workflow file; if Actions are enabled, later pushes can initiate collection. Newly created forks and forks synchronized with an affected upstream repository can also inherit the malicious workflow.

Private forks and downstream mirrors are particularly exposed because they may contain credentials committed to internal codebases. Every workflow run also returns a repository identifier even when no secret is found, giving the operator visibility into reachable execution contexts.

Organizations should inspect repositories for either workflow from August 31, 2026 onward and assume compromise if one is present. The practical response is to revoke the compromised GitHub credential, rotate potentially exposed credentials, remove the workflow from all branches, and examine forks and mirrors before further GitHub Actions runs.

#githubsecurity#supplychain#credentialtheft#devsecops
Open analytics
On the site 0 views
min read 4 09.10.2026
Instagram

GhostAction Workflows Spread Credential Theft Across GitHub Repositories

Open the post on Instagram ↗