GhostAction returns: hijacked maintainer accounts push credential-stealing GitHub Actions workflows at scale
A supply chain campaign that abuses GitHub Actions to harvest secrets has resurfaced, and it is spreading faster than before. Researchers report that attackers took over the GitHub accounts of trusted open-source maintainers and used them to commit a fake "security" workflow into hundreds of repositories within hours. As of October 9, 2026, the workflow had shown up across tens of thousands of repositories.
What happened
According to StepSecurity, the attackers first used the account of the author of pyxel, a popular game engine with about 18,400 stars, to commit a malicious workflow to 27 repositories. Roughly eight hours later, the account of the original author of Uber's athenadriver pushed the same file to 318 repositories in a 16-minute burst. Socket has since counted more than 500 GitHub accounts that committed the workflow to tens of thousands of repositories since October 7.
Researchers link the activity to GhostAction, a campaign first exposed in 2025. GitGuardian separately tracked a wave that reached 772 public repositories belonging to 373 users and organizations between August 31 and September 30, 2026.
The researchers describe this sequence:
- Account takeover. The attacker gets a maintainer's GitHub credentials, most likely a personal access token (PAT) leaked through infostealer logs or credential dumps.
- Reconnaissance. The repository's workflows are read to find out which named secrets exist.
- Injection. A workflow called Security Audit (
security-audit.yml) or GitHub Actions Security (github_actions_security.yml) is committed to the default branch under the victim's own identity. - Exfiltration. The workflow runs on
workflow_dispatchand on any push to any branch or tag. It does a full-history checkout, collects the repository's named secrets, and scans the working tree and the entire git history for 13 credential patterns (AWS, AI providers, source control, SaaS and cloud API keys). It pairs AWS key IDs with their secret keys and sends the results withcurlover plain HTTP to a hard-coded IP address (193.32.204[.]199).
The targeted data includes CI/CD secrets, AWS keys, Anthropic, OpenAI and OpenRouter API keys, GitHub and GitLab tokens, and in earlier waves SSH keys, Azure and Google Cloud credentials, container registry, database, npm, PyPI and Cloudflare credentials, and chat-bot tokens. In at least one case the attackers also modified a project's Docker image to include the XMRig cryptominer. Researchers say no malicious package releases had been published with the stolen publishing credentials at the time of their reports.
Why it matters
- The commit looks legitimate. The malicious file is pushed by a real, trusted maintainer, so the usual "unknown contributor" warning signs are missing.
- Deleted secrets are still exposed. Because the workflow reads the full git history, credentials that were committed and later "removed" can be stolen.
- Forks spread it. Socket notes that 279 forks in one compromised namespace already carry the workflow. Downstream forks that sync with an infected upstream can inherit it, and private forks and mirrors are the most exposed because that is where real credentials tend to be committed.
- The attacker gets a map even without secrets. Every run reports back a repository identifier, giving the operator a list of places where it can execute code.
What to do
- Hunt for the files. Search every repository, branch and fork (public and private) for
security-audit.ymlandgithub_actions_security.yml, or for any unexpected workflow added since August 31, 2026. Review Actions run logs for unexpected runs. - Assume compromise if found. Revoke the GitHub credential used to push it, then rotate every secret the repository could reach: Actions secrets, cloud keys, registry and package-publishing tokens, AI API keys, and anything ever committed to history.
- Remove it everywhere. Delete the workflow from all branches and check forks and mirrors. Disable Actions on forks that don't need them.
- Block the indicator. Block and alert on egress to
193.32.204[.]199from CI runners, and review past connections. - Harden maintainer identity. Replace classic PATs with short-lived, fine-grained tokens, enforce MFA/passkeys, and treat infostealer exposure of developer machines as a credential incident.
- Lock down workflows. Require reviewed pull requests and CODEOWNERS for
.github/workflows/, enable branch protection on default branches, setGITHUB_TOKENpermissions to read-only by default, and prefer OIDC over long-lived cloud secrets. - Scan your history. Run secret scanning across the full git history, not just the latest commit, and rotate anything it finds.
Sources: reporting by The Hacker News (October 9, 2026), based on research from StepSecurity, Socket and GitGuardian.
