The GhostAction supply-chain campaign compromised 327 GitHub users and inserted malicious workflows into 817 repositories, stealing 3,325 CI/CD secrets. Workflows masquerading as “Github Actions Security” sent PyPI, npm, DockerHub, GitHub, AWS, database, and Cloudflare credentials by HTTP POST to attacker infrastructure, including 45.139.104.115; a later wave added exfiltration domains and hundreds of commits. Although no malicious package releases had been confirmed at disclosure, 24 affected packages—nine npm and 15 PyPI—remained at immediate risk, while some stolen credentials were reportedly already abused.
CI/CD workflows are also vulnerable to remote-code-execution exposure from unsafe pull_request_target configurations, artifact-token leaks such as ArtiPACKED, and attacks including HackerBot-Claw. Elastic Security Labs released the open-source cicd-abuse-detector to review GitHub Actions, GitLab CI, and Azure DevOps changes before merge or deployment, extracting more than 50 signals from pipeline files and analyzing diffs for secret exfiltration, privileged pull-request triggers, permission escalation, self-hosted-runner targeting, supply-chain manipulation, and timestamp abuse. The tool can issue pull-request, issue, Slack, and Elasticsearch alerts and optionally block risky pull requests.

Trace attribution and downstream blast radius.
9 events from the most recent confirmed update back to the earliest known activity.
The automated HackerBot-Claw campaign scanned public repositories for pull_request_target misconfigurations and used techniques including poisoned Go init() functions, command injection, direct script injection, and AI prompt injection. In its most severe reported case, Aqua Security's Trivy repository was fully compromised, leading to a downstream supply-chain attack exposing 33,000 secrets across nearly 7,000 machines.
The primary GhostAction exfiltration hostname, bold-dhawan.45-139-104-115.plesk.page, stopped resolving at 4:15 PM. The campaign had sent stolen secrets to infrastructure associated with IP address 45.139.104.115.
GitGuardian notified the security teams at GitHub, npm, and PyPI about GhostAction at 3:50 PM and created alert issues for affected repositories. It identified 24 packages at immediate risk of compromise, though no malicious package releases had been confirmed.
PyPI placed FastUUID in read-only status at 12:11 after GitGuardian reported the incident. The compromised FastUUID user reverted the malicious commit at 12:30.
GitGuardian identified the GhostAction supply-chain campaign while investigating FastUUID, finding malicious GitHub Actions workflows across hundreds of repositories. The campaign ultimately affected 327 GitHub users and 817 repositories and stole 3,325 CI/CD secrets.
GitHub user Grommash9 pushed a malicious commit titled “Add Github Actions Security workflow” to FastUUID. The injected workflow exfiltrated a PyPI token to attacker-controlled infrastructure.
The Shai-Hulud npm worm harvested GitHub Personal Access Tokens, conducted secret reconnaissance with TruffleHog, and propagated through packages owned by compromised developers. Its first wave published more than 46,000 malicious packages.
Elastic Security Labs released cicd-abuse-detector, an open-source CI/CD review template for GitHub Actions, GitLab CI, and Azure DevOps. The tool analyzes pipeline-related diffs and metadata for risky changes, produces schema-validated LLM verdicts, and can alert, gate pull requests, or export findings to Elasticsearch.
GitGuardian observed a second GhostAction wave involving approximately 500 new commits, largely against repositories already compromised in the first wave. The attackers used new exfiltration domains, including carte-avantage.com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceorca.security
Open sourceorca.security
Open sourceblog.gitguardian.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.