GhostAction: a continuing supply-chain campaign with new bursts of activity
Security researchers are tracking a renewed wave of credential-theft activity attributed to the GhostAction campaign that first surfaced in September 2025. StepSecurity reported two concentrated bursts on October 7, 2026: one beginning at 13:20 UTC using the account of Takashi Kitao, which affected 27 repositories, and a second eight hours later using the account of Henry Wu (henrywoo), which pushed the same workflow to 318 repositories in a 16-minute window, 21:10–21:26 UTC.
Other trackers report different slices of the same activity. Socket said on October 9, 2026 that it had identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026. Earlier reporting by GitGuardian said GhostAction pushed the workflow to 772 public repositories belonging to 373 users and organizations between August 31 and September 30, 2026. An earlier incident set attributed to the campaign impacted 817 repositories across 327 GitHub users and resulted in exfiltration of 3,325 secrets, according to published findings cited by researchers.
How the malicious GitHub Actions workflows operate
Researchers say the injected workflows use filenames such as Security Audit ("security-audit.yml") or GitHub Actions Security ("github_actions_security.yml") and are designed to harvest credentials and send them to a hard-coded IP address over plain HTTP: 193.32.204[.]199.
The reported attack chain unfolds in four high-level steps: the attacker first obtains a maintainer's GitHub credentials—most likely a leaked personal access token (PAT) from infostealer logs or credential dumps—then scans the repository's workflow files for secrets as reconnaissance, injects a workflow into the default branch under the victim's identity, and finally runs an embedded payload that extracts data and sends it to the attacker-controlled endpoint via curl.
StepSecurity described the malicious workflow's runtime behavior: it triggers on workflow_dispatch and on an unfiltered push (any branch, any tag), checks out with fetch-depth: 0, and runs a single 'Audit' step that does four things:
- Append the repository's named GitHub Actions secrets found during reconnaissance;
- Scan the working tree for 13 credential patterns associated with AWS keys, AI services, source control services, and SaaS and cloud API keys;
- Check the entire git history for the same 13 patterns to harvest credentials that may have been committed and later deleted;
- Pair AWS access key IDs with their matching secret access keys.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat was taken — and where the risk shows up
The captured data, researchers report, includes the repository's named GitHub Actions secrets and a wide range of credentials from the working tree and full git history: CI/CD secrets, cloud, SaaS, and AI credentials such as AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens. Across previous GhostAction activity, the injected workflows targeted 2,577 secrets, including SSH private keys, Azure credentials, DockerHub and GHCR container registry credentials, database and FTP credentials, Google Cloud and Firebase credentials, Telegram, Slack, and Discord bot tokens, and keys associated with Cloudflare, npm, PyPI, and AI providers.
Researchers also documented at least one case where the attackers modified a repository—kuafuai/DevOpsGPT—to embed an XMRig cryptocurrency miner in its Docker image on August 30, 2026. At the time of reporting, no malicious package releases had been published using compromised publishing credentials.
Practical remediation steps researchers recommend
Developers are advised to check repositories for either security-audit.yml or github_actions_security.yml added since August 31, 2026 and, if present, to assume compromise. Published recommendations repeated by researchers include:
- Revoke the compromised GitHub credential (for example, the PAT used to commit the workflow) and rotate any credentials that might have been exposed.
- Delete the malicious workflow from all branches and inspect forks of infected repositories for copies of the workflow file.
- Check downstream forks and mirrors; Socket warned that "the 279 forks in the henrywoo namespace each carry the workflow file" and that if Actions are enabled, subsequent pushes can trigger credential harvesting.
What this means for open-source maintainers, security teams, and downstream forks
Open-source maintainers: If a repository contains one of the identified workflow files added since August 31, 2026, maintainers should assume their publishing and CI credentials may have been exposed and follow the steps above to revoke and rotate credentials and remove the workflow.
Security teams and enterprise CI/CD owners: The workflows scan fetch-depth: 0 and the complete git history, so security teams should prioritize checking repository histories and named Actions secrets, and treat private forks and mirrors as high-risk because "private repositories are where committed credentials are actually found."
Downstream forks and mirrors: Researchers warned that downstream forks inherit risk either when created or when synchronized with an infected upstream repository, and that every workflow run also returns a repository identifier even when no credentials are stolen—providing attackers with a map of reachable execution contexts independent of credential theft.
GhostAction's renewed bursts and the breadth of credentials targeted underscore a persistent threat model: attackers leveraging leaked maintainer credentials to plant code that harvests secrets across both visible public projects and more sensitive private forks. The immediate, concrete tasks—scan for the named workflow files, revoke exposed tokens, rotate credentials, and purge the malicious workflows from all branches and forks—are both precautionary and essential to halt ongoing exfiltration.




