Cybersecurity researchers have uncovered fresh details regarding an ongoing, sophisticated credential-theft campaign that has successfully hijacked high-profile open-source developer accounts. The threat actors leveraged these compromised credentials to inject malicious workflows into hundreds of repositories, putting downstream users, enterprise developers, and sensitive cloud infrastructure at risk on a massive scale.
According to security telemetry analyzed by StepSecurity, the attackers targeted and compromised the account of Takashi Kitao, the author of the widely recognized 18,400-star game engine Pyxel. Using Kitao’s credentials, the adversary pushed a malicious workflow across 27 distinct repositories starting at 13:20 UTC. Just eight hours later, the campaign struck again, utilizing the account of Henry Wu (known as henrywoo), the original author of Uber’s athenadriver. The attackers deployed the exact same malicious workflow to a staggering 318 repositories within a remarkably brief 16-minute window between 21:10 and 21:26 UTC.
The scope of this ongoing operation extends even further. Dependency and supply chain security firm Socket reported that, as of October 9, 2026, it had identified more than 500 individual GitHub accounts that committed the malicious workflow to tens of thousands of repositories in a wave starting on October 7.
Security researchers have firmly attributed this malicious activity to GhostAction, a prominent supply chain attack campaign that initially came to public attention in September 2025. During its earlier iterations, the campaign impacted 817 repositories across 327 GitHub users, successfully exfiltrating 3,325 secrets. Among the compromised information were critical authentication tokens for major packaging and container registries such as PyPI, npm, and DockerHub, all harvested directly through compromised developer accounts.

The mechanics of the current attacks closely mirror previous incidents associated with the GhostAction group. In both recent high-profile accounts, the attackers introduced a rogue GitHub Actions workflow named either "Security Audit" (security-audit.yml) or "GitHub Actions Security" (github_actions_security.yml). Designed with malicious intent, these automated scripts immediately initiate an exfiltration routine, transmitting sensitive data over plain HTTP to a hard-coded external Internet Protocol address located at 193.32.204[.]199.
The data swept up by these malicious workflows is extensive and deeply concerning. It includes the targeted repository’s configured GitHub Actions secrets, crucial CI/CD pipeline credentials, as well as a wide array of cloud, artificial intelligence, and Software-as-a-Service credentials. Because the workflows check out the codebase with unrestricted history and inspect the working tree, they manage to vacuum up sensitive entries from the entire Git history. This includes high-value secrets such as Amazon Web Services access keys, Application Programming Interface keys for AI platforms like Anthropic, OpenAI, and OpenRouter, alongside personal access tokens for GitHub and GitLab.
Detailing the exact lifecycle of the attack, researchers noted that the injected workflow is engineered to trigger automatically under multiple conditions, including the workflow_dispatch manual event and unfiltered pushes across any branch or tag. Upon execution, the workflow checks out the repository with full history depth using fetch-depth: 0 and runs a specialized audit script. This script systematically searches the environment, local files, and historical commits to harvest targeted credentials before transmitting them to the external server.
The resurgence of GhostAction follows closely on the heels of reports published earlier in the week by GitGuardian, which documented that the campaign had previously pushed the identical malicious workflow to 772 public repositories belonging to 373 distinct GitHub users and organizations between August 31 and September 30, 2026.

Analysis of the workflows utilized across these campaigns reveals a sweeping target list designed to capture up to 2,577 distinct types of secrets. Beyond the standard cloud and AI tokens, the injected code hunts for Secure Shell private keys, Microsoft Azure credentials, Docker Hub and GitHub Container Registry tokens, database credentials, File Transfer Protocol passwords, Google Cloud and Firebase service keys, Telegram, Slack, and Discord bot tokens, as well as keys tied to Cloudflare, npm, and PyPI infrastructure.
While the primary objective of the campaign appears to be silent credential harvesting, the threat actors have occasionally demonstrated a willingness to expand their operational impact. In at least one documented instance observed on August 30, 2026, attackers compromised the kuafuai/DevOpsGPT repository and altered it to embed an XMRig cryptocurrency miner directly into the project’s official Docker container image. However, security analysts noted that, as of the time of reporting, no malicious software packages have been formally published to public repositories using these compromised publishing credentials.
In response to the rapid spread of the campaign, software security experts are urging developers and maintainers to immediately audit their repositories. Teams are advised to check their codebases for the presence of either of the two malicious GitHub workflow files introduced since August 31, 2026. If these workflows are detected, organizations must treat their systems as fully compromised. Immediate remediation steps include revoking all compromised GitHub and third-party credentials, rotating exposed API keys and tokens, completely removing the malicious workflow files from all active and inactive branches, and verifying the security status of any forks derived from the infected repositories.
The threat posed by downstream forks is particularly acute. Socket researchers pointed out that the 279 forks residing within the henrywoo namespace each carry the rogue workflow file. If GitHub Actions remain enabled on these forked projects, any subsequent code pushes can inadvertently trigger credential harvesting operations. Furthermore, downstream forks remain perpetually vulnerable if they inherit the malicious workflow during creation or by synchronizing their codebases with an affected upstream repository.

Security experts emphasize that private forks and internal mirrors represent some of the highest-risk environments in this campaign. Because private repositories are frequently where developers inadvertently commit high-privilege production credentials, they provide a lucrative hunting ground for attackers. Additionally, researchers noted that across both compromised major accounts, every execution of the malicious script returns a unique repository identifier back to the attacker—regardless of whether actual secrets were discovered during the run. This mechanism ensures that the malicious operators maintain an accurate, comprehensive map of reachable execution contexts across the global developer ecosystem, independent of direct credential theft.
