Cybersecurity researchers have disclosed critical new details regarding an ongoing and highly coordinated credential-theft campaign that has successfully compromised high-profile open-source developer accounts to inject malicious automated workflows into tens of thousands of software repositories. The sophisticated operation, known widely in the threat-intelligence community as GhostAction, underscores persistent vulnerabilities in modern software supply chains and the increasing reliance on automated CI/CD pipelines as vectors for lateral movement and data exfiltration.
According to telemetry and incident reports shared by cybersecurity firms StepSecurity and Socket, the latest wave of the campaign leveraged the trusted credentials of prominent open-source maintainers to distribute malicious GitHub Actions workflows. The attackers targeted accounts associated with major software projects, rapidly scaling their reach across multiple codebases within tight operational windows designed to evade immediate detection by repository owners and automated monitoring tools.
Detailing the timeline of the recent intrusions, StepSecurity revealed that the attackers first hijacked the account of Takashi Kitao, the acclaimed author of the popular 18,400-star retro game engine Pyxel. Beginning at 13:20 UTC, the threat actors utilized Kitao’s compromised credentials to push a malicious workflow file to 27 distinct repositories. Just eight hours later, the campaign expanded significantly when the account of Henry Wu—known as henrywoo and recognized as the original author of Uber’s athenadriver project—was similarly compromised. In a rapid 16-minute window between 21:10 and 21:26 UTC, Wu’s account was forced to push the exact same malicious workflow to a staggering 318 repositories.

The scope of the operation has widened substantially since these initial account takeovers. Socket reported that by October 9, 2026, its threat-hunting systems had identified more than 500 distinct GitHub accounts that had committed the malicious workflow to tens of thousands of repositories in a wave that began days earlier on October 7. This expansive distribution highlights a systemic threat to collaborative coding platforms, where a single compromised maintainer profile can instantly pollute downstream dependencies and connected development environments.
The GhostAction activity itself is not entirely new to the cybersecurity landscape. The supply chain campaign first came to light in September 2025, when researchers exposed an initial wave that impacted 817 repositories across 327 GitHub users. That early iteration resulted in the successful exfiltration of 3,325 sensitive secrets, including active authentication tokens for major package registries such as PyPI, npm, and DockerHub, all harvested directly through compromised developer accounts.
In this latest iteration, the mechanics of the attack remain consistent with earlier observations. Both newly compromised accounts were found to inject a workflow disguised as a routine security audit, bearing names such as "Security Audit" or "GitHub Actions Security" through configuration files named "security-audit.yml" or "github_actions_security.yml". Once integrated into a repository, these automated scripts are engineered to siphon sensitive internal data and transmit it over plain HTTP to a hard-coded external IP address identified as 193.32.204.199.

The data captured by these rogue workflows extends far beyond basic repository metrics. The injected scripts are designed to harvest named GitHub Actions secrets, including critical CI/CD credentials, alongside a wide array of cloud infrastructure, artificial intelligence, and Software-as-a-Service credentials located anywhere within the working tree or the complete Git history. This includes high-value assets such as AWS access keys, proprietary API keys for providers like Anthropic, OpenAI, and OpenRouter, as well as administrative authentication tokens for GitHub and GitLab.
Security analysts breaking down the attack chain note that the malicious workflow is triggered dynamically upon specific repository events, including workflow_dispatch and unfiltered push commands across any branch or tag. The script initiates a checkout process utilizing a deep fetch parameter to capture the entire commit history, executing an audit step that systematically sweeps the environment for valuable authentication material.
This recent surge follows closely on the heels of another major disclosure earlier in the week, when GitGuardian reported that the GhostAction campaign had successfully pushed its malicious workflows to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026. According to those findings, the injected routines were configured to target an even broader matrix of 2,577 distinct secrets. This exhaustive list encompasses SSH private keys, Azure cloud credentials, container registry tokens for DockerHub and GHCR, database connection strings, FTP access credentials, Google Cloud and Firebase keys, and bot tokens for messaging platforms like Telegram, Slack, and Discord, alongside keys tied to Cloudflare and various package managers.

Beyond pure credential harvesting, threat actors associated with the broader campaign have occasionally demonstrated more disruptive intent. In at least one documented case observed on August 30, 2026, attackers altered the "kuafuai/DevOpsGPT" repository to embed an XMRig cryptocurrency mining utility directly into the project’s official Docker image. However, researchers note that as of the time of reporting, no malicious package releases have been officially published using stolen package-publishing credentials in this latest cycle, suggesting the primary objective remains widespread espionage and credential aggregation.
In response to these unfolding events, cybersecurity professionals and platform maintainers are urging developers to immediately audit their repositories. Project owners are advised to check all codebases for the presence of the unauthorized GitHub workflow files introduced since August 31, 2026, and to treat any detected instances as a confirmed compromise. Remediation guidelines recommend immediately revoking compromised GitHub credentials, rotating all exposed API keys and cloud secrets, purging the malicious workflow files from all branches, and thoroughly inspecting any downstream forks of the infected repositories.
The risk posed by downstream forks remains a critical concern for enterprise security teams. Socket warned that the 279 forks residing within the henrywoo namespace each carry the unauthorized workflow file, meaning that if GitHub Actions remain enabled on those derivative projects, subsequent pushes or synchronization events could automatically trigger credential harvesting operations. Private forks and organizational mirrors are deemed the most vulnerable, as private environments frequently house the active, production-grade credentials that attackers seek to exploit. Furthermore, security analysts pointed out that every execution of the malicious workflow reports a repository identifier back to the command-and-control infrastructure, providing the operators with a comprehensive operational map of reachable execution contexts regardless of whether a specific repository contained harvestable secrets.
