GhostAction Supply Chain Attack Compromises High-Profile Open-Source Accounts to Push Malicious Workflows

Cybersecurity researchers have disclosed critical details regarding an ongoing, sophisticated credential-theft campaign that has successfully compromised two high-profile open-source maintainer accounts. The attackers leveraged these compromised accounts to inject and push a malicious workflow into more than 340 code repositories, marking a significant escalation in ongoing supply chain threats targeting developer ecosystems.

According to analysis shared by cloud security firm StepSecurity, the operation began utilizing the account of Takashi Kitao, the author of the widely recognized, 18,400-star game engine Pyxel. Beginning at 13:20 UTC, the threat actor used Kitao’s credentials to push a malicious workflow across 27 distinct repositories. Just eight hours later, the campaign struck again. The account of Henry Wu (known on GitHub as henrywoo), the original author of Uber’s athenadriver, was hijacked to push the exact same malicious workflow to an astonishing 318 repositories. This second wave of attacks was executed in a tightly compressed 16-minute window between 21:10 and 21:26 UTC.

The sheer scale of the campaign extends far beyond these two primary incidents. Software supply chain security firm Socket reported that, as of October 9, 2026, it has identified more than 500 individual GitHub accounts that have committed the malicious workflow to tens of thousands of repositories since October 7, 2026. This sprawling network of compromised accounts and repositories points to a well-organized, highly automated assault on developer infrastructure.

Security analysts have attributed this malicious activity to GhostAction, a massive supply chain attack campaign that first came to public attention in September 2025. During its initial wave of activity, the GhostAction campaign impacted 817 repositories across 327 GitHub users. That initial breach resulted in the catastrophic exfiltration of 3,325 sensitive secrets, including vital publishing tokens for major ecosystems like PyPI, npm, and DockerHub, all harvested directly through compromised developer accounts.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Mirroring the tactics observed in earlier iterations, the recent attacks rely on pushing a deceptively named workflow file—either "Security Audit" (security-audit.yml) or "GitHub Actions Security" (github_actions_security.yml). Despite their innocuous-sounding names, these automated workflows are meticulously designed to harvest sensitive data and exfiltrate it over plain HTTP to a hard-coded external IP address (193.32.204[.]199).

The scope of data captured by these rogue workflows is extensive. The payloads target a repository’s named GitHub Actions secrets, including critical CI/CD credentials, alongside cloud, AI, and SaaS API keys present anywhere within the working tree and the entire Git history. Among the prized targets are AWS access keys, API keys for platforms like Anthropic, OpenAI, and OpenRouter, as well as authentication tokens for GitHub and GitLab.

Security researchers detailing the mechanics of the attack note that the malicious workflow triggers automatically on workflow_dispatch events and unfiltered pushes across any branch or tag. The script checks out code using fetch-depth: 0 to ensure access to the complete repository history before executing a streamlined audit step that scans for environmental secrets and transmits them to the attacker’s infrastructure.

This latest surge follows closely on the heels of a report published earlier this week by GitGuardian, which revealed that the GhostAction campaign had previously pushed the malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

An analysis of the injected workflows from that timeframe highlights an even broader appetite for developer secrets, targeting up to 2,577 distinct categories of sensitive information. Beyond standard cloud and AI credentials, the targeted data includes SSH private keys, Azure credentials, credentials for container registries like DockerHub and GHCR, database connection strings, FTP credentials, Google Cloud and Firebase keys, messaging bot tokens for Telegram, Slack, and Discord, and keys associated with Cloudflare, npm, and PyPI.

The threat actors behind GhostAction have not limited their activities strictly to passive credential harvesting. In at least one troubling case observed on August 30, 2026, researchers found that attackers modified the kuafuai/DevOpsGPT repository to embed a malicious XMRig cryptocurrency miner directly into the project’s Docker image. However, security analysts note that as of the time of reporting, no malicious package releases have been published using compromised publishing credentials, suggesting the primary objective remains widespread intelligence gathering and credential exfiltration.

In response to the ongoing threat, cybersecurity experts strongly advise developers to immediately audit their repositories for the presence of either of the two suspect GitHub workflow files introduced since August 31, 2026. Organizations and maintainers finding these files should treat their systems as compromised. Recommended remediation steps include immediately revoking exposed GitHub credentials, rotating all associated API keys and secrets, removing the malicious workflow from every active branch, and thoroughly inspecting downstream forks of infected repositories.

Security firms have emphasized that downstream risks remain a critical concern, particularly given the proliferation of forks. Socket pointed out that the 279 forks residing within the henrywoo namespace each carry the malicious workflow file. If GitHub Actions are enabled on these forks, subsequent pushes can easily trigger automated credential harvesting. Furthermore, downstream forks remain vulnerable if they inherit the malicious workflow either upon creation or by synchronizing with an affected upstream repository.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Private forks and downstream mirrors represent some of the most exposed assets in these campaigns, as private repositories are precisely where developers are most likely to store hard-coded production credentials. Compounding the risk, researchers noted that across both compromised accounts, every execution of the malicious workflow returns a repository identifier regardless of whether any credentials were successfully unearthed. This mechanism ensures that the threat operators maintain an accurate, comprehensive map of reachable execution contexts completely independent of successful credential theft.

Leave a Reply

Your email address will not be published. Required fields are marked *