Cybersecurity researchers have disclosed critical details regarding an ongoing and sophisticated credential-theft campaign that has successfully compromised high-profile open-source maintainer accounts. The attackers leveraged these trusted accounts to clandestinely inject malicious GitHub Actions workflows into hundreds of repositories, putting tens of thousands of downstream projects and thousands of sensitive secrets at risk of immediate exfiltration.
According to intelligence shared by security firm StepSecurity, the latest phase of the campaign unfolded when attackers gained unauthorized access to the developer account of Takashi Kitao, the widely recognized author of the 18,400-star game engine Pyxel. Beginning at 13:20 UTC, the threat actor utilized Kitao’s compromised account to push a malicious workflow across 27 distinct repositories. Just eight hours later, the campaign struck a second prominent target: the account of Henry Wu, known online as henrywoo and recognized as the original author of Uber’s athenadriver. Within a tightly compressed sixteen-minute window between 21:10 and 21:26 UTC, Wu’s account was similarly abused to push the identical malicious workflow into an additional 318 repositories.
The scale of this operation extends far beyond these two initial developer accounts. Supply chain security platform Socket reported that by October 9, 2026, it had identified more than 500 distinct GitHub accounts that had committed the malicious workflow to tens of thousands of repositories in a wave of activity dating back to October 7.

This malicious activity has been definitively attributed by security analysts to GhostAction, a massive and persistent supply chain attack campaign that first came to public attention in September 2025. During its initial wave, the GhostAction campaign impacted 817 repositories across 327 GitHub users, resulting in the successful exfiltration of 3,325 sensitive secrets, including vital deployment and packaging tokens for PyPI, npm, and DockerHub, all harvested through compromised developer accounts.
In the current wave of attacks, the mechanics mirror those observed in previous operations. Both newly compromised accounts were found to push a rogue workflow named either "Security Audit" under the filename "security-audit.yml" or "GitHub Actions Security" under the filename "github_actions_security.yml". These files are deceptively crafted to blend in with standard repository maintenance tools while quietly executing unauthorized data harvesting scripts designed to transmit sensitive information over plain HTTP to a hard-coded external IP address identified as 193.32.204.199.
The data targeted and captured by these malicious workflows is comprehensive and highly sensitive. It includes the repository’s named GitHub Actions secrets, crucial CI/CD pipeline secrets, and a wide array of cloud computing, artificial intelligence, and Software-as-a-Service credentials located anywhere within the working tree and the complete Git history. Among the prized targets are AWS access keys, API keys for AI providers such as Anthropic, OpenAI, and OpenRouter, as well as high-privilege tokens for platforms like GitHub and GitLab.
The operational sequence of the attack is designed for immediate and automated execution. According to insights provided by StepSecurity, the injected workflow is configured to trigger automatically on standard workflow events such as workflow_dispatch and unfiltered pushes across any branch or tag. Upon execution, it performs a complete repository check out with a fetch depth of zero, allowing it to inspect the entire historical record of the codebase. It then runs a specialized audit step that systematically scrapes local environment variables, configuration files, and historical commits for hard-coded secrets, immediately packaging and transmitting the stolen material to the attacker’s infrastructure.

This ongoing wave follows closely on the heels of reports published earlier in the week by GitGuardian, which documented that the GhostAction campaign had previously pushed the same malicious workflow to 772 public repositories belonging to 373 distinct GitHub users and organizations between August 31 and September 30, 2026.
An analysis of the workflows injected during these earlier phases reveals an even broader targeting scope, encompassing up to 2,577 distinct categories of secrets. Beyond standard cloud and AI credentials, the targeted data includes SSH private keys, Azure credentials, credentials for container registries like DockerHub and GHCR, various database access credentials, FTP configurations, Google Cloud and Firebase credentials, Telegram, Slack, and Discord bot tokens, and specialized keys associated with Cloudflare, npm, and PyPI.
Furthermore, the flexibility and resourcefulness of the GhostAction operators have occasionally extended beyond mere credential harvesting. In at least one notable incident observed on August 30, 2026, threat actors actively tampered with the "kuafuai/DevOpsGPT" repository to covertly embed an XMRig cryptocurrency miner directly into the project’s Docker image. Despite the widespread compromise of developer accounts and repositories, security researchers note that, as of the time of writing, no malicious software package releases have yet been published using the compromised publishing credentials, though the risk remains exceptionally high.
In light of these developments, cybersecurity professionals and software developers are strongly advised to immediately audit their repositories. Development teams should check their codebases for the presence of either of the two identified GitHub workflow files introduced since August 31, 2026. If these files are discovered, organizations must treat the affected environment as fully compromised. Recommended remediation steps include revoking all exposed GitHub credentials, rotating cloud and API secrets, permanently deleting the malicious workflow files from all active and historical branches, and thoroughly inspecting any downstream forks of the infected repositories.

The danger posed by forks and mirrors cannot be overstated, as malicious workflows can easily persist and spread through routine development practices. Socket pointed out that the 279 forks residing within the henrywoo namespace each carry the malicious workflow file. If GitHub Actions are enabled on those secondary copies, subsequent code pushes can easily trigger credential harvesting operations. Furthermore, downstream forks remain at significant risk if they inherit the rogue workflow either during their initial creation process or by synchronizing with an affected upstream repository.
Security analysts emphasize that private forks and downstream mirrors represent the areas of highest exposure. Because private repositories are frequently where developers inadvertently commit production-grade credentials, they offer the most lucrative target for attackers. Across both of the recently compromised accounts, every workflow execution also returns a unique repository identifier regardless of whether any specific secrets are discovered during the scan. This allows the operators to maintain a comprehensive and up-to-date map of reachable execution contexts, independent of whether credential theft was successful in any individual instance.
As the investigation into the GhostAction campaign continues, maintainers of open-source projects and enterprise development teams alike are urged to implement stricter access controls, mandate multi-factor authentication across all code-hosting platforms, and continuously monitor their CI/CD pipelines for unauthorized configuration modifications.
