GhostAction is a software supply chain intrusion campaign focused on CI/CD abuse in GitHub repositories. In September 2025, the campaign compromised hundreds of GitHub user accounts and modified workflow definitions across hundreds of repositories to harvest secrets from automated build environments. The operation injected malicious GitHub Actions workflow logic that exfiltrated credentials and other sensitive tokens from CI runs, enabling follow-on access into developer, cloud, and production environments. The campaign is associated with compromise of maintainer accounts followed by unauthorized workflow-file changes, making it a notable example of attacker tradecraft shifting from direct server intrusion toward abuse of trusted development automation. Reported impact included more than 3,300 stolen secrets across at least 817 repositories, with downstream exposure affecting open-source packages in both npm and PyPI ecosystems. Public reporting assessed GhostAction as distinct from the earlier s1ngularity GitHub account compromise activity. GhostAction’s observed behavior aligns with initial access through stolen developer credentials, persistence via malicious workflow modifications, credential theft and exfiltration from CI/CD environments, and post-compromise pivoting into broader software supply chain and cloud contexts. High-value targets in this model include repository secrets, package publishing credentials, cloud access tokens, code-signing material, deploy keys, and other automation-linked credentials. No high-confidence attribution to a specific country, organization, or state sponsor is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised GitHub accounts and repositories to inject malicious workflow files that exfiltrated CI/CD secrets at scale.
GhostAction is a supply chain attack campaign on GitHub, compromising maintainer accounts and injecting malicious GitHub Actions workflows to exfiltrate secrets from repositories.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.