malware
Published 2026-10-07
Verified 2026-10-09

GhostAction is back: GitGuardian finds a secret-stealing GitHub Actions workflow pushed to 772 public repositories of 373 users and organisations between 31 August and 30 September, using the victims' own stolen accounts

GitGuardian reported on 7 October 2026 that GhostAction, the CI/CD supply-chain campaign it first exposed in September 2025, ran a new wave from 31 August 2026. Using what appear to be stolen GitHub credentials, the attacker committed a workflow named 'Github Actions Security' to 772 public repositories belonging to 373 GitHub users and organisations by 30 September; each workflow lists the repository's own secret names (scraped from earlier workflow history) and posts their values over plain HTTP to a bare IP address. Together the injected workflows target 2,577 secrets, most often SSH keys and Azure, AWS and database credentials. A variant named 'Security Check' (security-check.yml) appeared in seven repositories from 7 September and tags each theft with an injection ID. GitHub held most runs for approval: of 3,669 runs GitGuardian collected across 605 repositories, 499 executed in 32 repositories and 336 completed, exfiltrating 26 secrets from 13 repositories, with new runs still triggering. Only 124 repositories (16%) had been cleaned in public history by 5 October. In 92 cases the attacker simply re-pointed workflows left over from earlier waves, so GitGuardian says the campaign never really stopped. It also found 13 victim repositories used for GitHub Actions cryptomining by at least four other campaigns, including an XMRig miner hidden in the Docker image of the popular kuafuai/DevOpsGPT project, and thinks the stolen GitHub credentials are being traded among several actors. Researchers at Cynative independently spotted the commits. Primary: GitGuardian; wire: SecurityWeek.

Product
GitHub repositories and GitHub Actions secrets (CI/CD pipelines)
Versions
n/a — campaign using stolen GitHub credentials; no product CVE
Exploited in Australia?
unknown
Patch to
Search your repositories for workflows named 'Github Actions Security' or 'Security Check' and for commits that add or edit them; delete them, rotate every secret the workflow referenced, and revoke GitHub tokens and sessions for the account that pushed the commit. Require approval for workflow runs from new contributors, protect default branches and use short-lived OIDC credentials instead of long-lived cloud keys.

Primary: GitGuardian — GhostAction GitHub Actions supply chain attack returns (7 Oct 2026) · SecurityWeek — In Other News: GhostAction secret theft spreads to 772 more GitHub repos (9 Oct 2026)

tech cloud identity