The GhostAction supply-chain campaign compromised 772 public GitHub repositories across 373 users and organizations between August 31 and September 30, 2026, targeting 2,577 CI/CD secrets. Attackers used stolen GitHub account access to inject legitimate-looking GitHub Actions workflows that collected selected secrets and sent them to attacker-controlled infrastructure. GitGuardian reported 336 successful malicious workflow runs and confirmed the theft of 26 secrets from 13 repositories; GitHub held most reviewed runs for approval, limiting execution.
Attackers also updated malicious workflows left behind by earlier campaign waves, demonstrating persistence. As of October 5, only 16% of affected repositories showed effective cleanup in public commit history, leaving uncertainty about remediation elsewhere. Affected organizations should remove malicious workflows, revoke compromised GitHub credentials, rotate potentially exposed secrets, and investigate repository access and workflow execution history. Defensive priorities, consistent with GitHub’s secure-use guidance, include least-privilege workflow permissions, stronger approval and workflow-change review controls, and hardened account security.

Trace attribution and downstream blast radius.
13 events from the most recent confirmed update back to the earliest known activity.
As of October 9, 2026, Socket had identified more than 500 GitHub accounts that committed malicious workflows to tens of thousands of repositories since October 7. Its findings substantially expanded the reported scope of the ongoing GhostAction credential-theft campaign.
On October 8, 2026, attackers used compromised maintainer accounts henrywoo and kitao to inject malicious security-audit.yml workflows into 346 repositories, including uber/athenadriver and kitao/pyxel. The workflows expanded beyond GitHub Actions secrets to scan source files and Git history for cloud, AI-service, source-control, and SaaS credentials, sending collected data in cleartext to 193.32.204[.]199.
On October 7, 2026, attackers using the compromised xxyangyoulin account attempted to retrigger the malicious typecho-fans/plugins workflow through an empty commit and a subsequent README edit. Both runs stopped in action_required because workflow approval was required, preventing execution.
GitGuardian recorded a further GhostAction activity burst affecting 103 public GitHub repositories on September 15.
GhostAction compromised 294 repositories on September 5, within a September 2–5 burst affecting roughly 400 repositories.
GhostAction affected 143 public GitHub repositories in a single activity burst. Attackers used stolen GitHub account access to inject malicious GitHub Actions workflows under victims' identities.
GhostAction used 170[.]39[.]218[.]2 for credential collection in March 2026, following its use during October–December 2025.
The attacker-controlled endpoint bold-dhawan.45-139-104-115.plesk.page stopped resolving at 16:15 UTC on September 5, 2025, shortly after public disclosure. Malicious GitHub Actions workflows had used the endpoint to receive stolen repository secrets.
GitGuardian disclosed GhostAction after the campaign compromised 817 public GitHub repositories and collected at least 3,325 secrets.
GitGuardian found cryptomining activity in kuafuai/DevOpsGPT, a repository subsequently affected by GhostAction, involving an XMRig binary disguised as /usr/local/bin/pyworker. Researchers did not attribute the two compromises to the same operator, citing differences in operational style.
GitGuardian's investigation identified 772 repositories compromised between August 31 and September 30, 2026, with 2,577 secrets targeted across 373 users and organizations. Reviewing 3,669 workflow runs, it found that most were held for approval, but 336 completed successfully and enabled confirmed theft of 26 secrets from 13 repositories.
Cynative researchers independently identified suspicious GitHub commits and contacted GitGuardian, prompting its investigation into the latest GhostAction activity.
During the latest wave, attackers updated existing malicious workflows in 92 cases rather than creating new ones, redirecting credential collection to 193[.]32[.]204[.]199. The workflows collected selected GitHub Actions secrets after legitimate repository pushes and transmitted them through HTTP POST requests.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
10 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcestepsecurity.io
Open sourcecybersecuritynews.com
Open sourceblog.gitguardian.com
Open sourcedocs.github.com
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.