GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A new wave of the GhostAction supply chain campaign has compromised 772 public GitHub repositories, using fake GitHub Actions workflow files to steal credentials from CI/CD environments.

The activity ran from August 31 through September 30, 2026, and targeted 2,577 secrets across 373 GitHub users and organizations, including cloud keys, SSH credentials, container registry logins, database passwords, and GitHub tokens.

GitGuardian’s investigation shows that the campaign uses stolen GitHub account access to add malicious workflows under the victim’s own identity.

The malicious files look like normal automation updates, making them easy to miss during a quick code review. In most cases, the actor added a workflow named github_actions_security.yml with the commit message Add Github Actions Security workflow.

The workflow waits for a normal repository push, reads selected GitHub Actions secrets, and sends them to attacker-controlled infrastructure through a curl POST request.

This technique resembles earlier fake CI update credential theft activity, where routine-looking workflow changes were used to access tokens and cloud credentials.

Analysts at GitGuardian identified the latest GhostAction activity after researchers at Cynative independently spotted suspicious commits and contacted the company.

GitGuardian first disclosed GhostAction in September 2025, when the campaign compromised 817 public repositories and collected at least 3,325 secrets.

The latest findings show that it was not a short-lived event: malicious workflows from earlier waves remained in some repositories and were later updated with fresh data-theft endpoints.

GhostAction Supply Chain Campaign Uses Malicious GitHub Actions

GhostAction does not simply collect every variable available to a workflow runner. Instead, the workflow appears to inspect a repository’s existing workflow and configuration history for secret references formatted as ${{ secrets.NAME }}.

It then inserts those exact secret names into the added workflow. This makes the malicious file more focused and allows it to collect credentials that are likely useful for deployment, publishing, cloud management, or source-code access.

The latest payload sends data over plain HTTP to 193.32.204.199, replacing older GhostAction infrastructure. A smaller variant seen in seven repositories used security-check.yml, displayed the workflow name “Security Check,” and used the commit message Add security check workflow.

That variant sent data to an API endpoint containing a unique injection identifier, which suggests the operator may be tracking stolen credentials by repository or workflow instance.

The use of hidden workflow persistence is also consistent with the Shai-Hulud npm supply chain attack, which injected GitHub Actions files to continue collecting secrets after an initial compromise.

GitGuardian recorded three major bursts in the new wave: 143 repositories on August 31; roughly 400 repositories between September 2 and 5, including 294 on September 5 alone; and 103 repositories on September 15. Of 3,669 workflow runs reviewed across 605 repositories, GitHub held most for approval.

Still, 499 ran in 32 repositories, and 336 runs completed successfully, allowing the theft of 26 secrets from 13 repositories. The most commonly targeted values were SSH private keys and deployment-server credentials, accounting for 446 secret references.

Azure credentials were targeted 218 times, while Docker Hub and GitHub Container Registry credentials appeared 142 times.

The workflows also sought database passwords, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, and API tokens for services such as Cloudflare, npm, PyPI, Slack, Telegram, Discord, and AI platforms.

This reflects the growing risk described in trusted developer tooling abuse, where developer systems and build pipelines are used as a route to cloud and source-code access.

GhostAction Campaign Never Fully Stopped

The campaign’s strongest sign of persistence is that, in 92 cases, the actor did not create a new workflow. Instead, they updated an already compromised file using the commit message Update Github Actions Security workflow.

These files had survived from earlier campaign periods and were modified to use the new collection server. Researchers linked the same workflow pattern to older endpoints, including bold-dhawan.45-139-104-115.plesk.page, carte-avantage.com, 170.39.218.2, and *.oast.fun Interactsh domains.

Only 124 of the 772 affected repositories, or 16%, had been effectively cleaned in public commit history as of October 5. That figure matters because a malicious workflow may run again whenever a developer pushes a legitimate commit.

Organizations should therefore treat removal of the workflow as only one part of the response. They must identify how the attacker gained repository write access, revoke the affected GitHub credential, review workflow runs and audit logs, and rotate every secret that may have been available to the runner.

GitHub advises teams to limit each workflow and GITHUB_TOKEN to the minimum permissions required, audit workflow source code and third-party actions, and pin actions to a full commit SHA, which provides an immutable reference.

Organizations should also use environment approval controls for sensitive deployment secrets and closely review newly added or modified files under .github/workflows/. GitHub’s secure-use guidance notes that an exposed secret must be rotated, even when it was masked in logs.

GitGuardian also found a cryptominer in the kuafuai/DevOpsGPT repository, which was later hit by GhostAction. However, the researchers did not attribute both events to the same operator.

The miner used a forged author email, a tailored payload, an XMRig binary disguised as /usr/local/bin/pyworker, and a different operational style, while GhostAction relied on broad, automated GitHub API workflow injection.

The overlap still highlights a key problem: stolen GitHub credentials can be reused by several unrelated threat groups. A compromised maintainer account may be used to collect CI/CD secrets, inject malicious code, publish altered packages, or run cryptomining workloads.

As recent software supply chain threat activity has shown, a single developer identity can become a path into build systems, cloud accounts, package registries, and downstream customer environments.

For defenders, the central lesson is identity control. Teams should not only remove suspicious workflow files and rotate cloud keys; they should revoke exposed GitHub personal access tokens, enforce phishing-resistant multi-factor authentication, require review for workflow changes, apply least-privilege permissions, and monitor outbound network traffic from CI runners.

In GhostAction incidents, leaving the original stolen GitHub credential active could allow the same operator—or another actor holding that credential—to return.

Indicators of compromise (IoCs):-

IoC Type Indicator Context
Malicious workflow file github_actions_security.yml Main GhostAction workflow injected into victim repositories
Workflow display name Github Actions Security Name used by the principal malicious workflow
Commit message Add Github Actions Security workflow Common commit message used to add the workflow
Commit message Update Github Actions Security workflow Used to modify an existing malicious workflow
Variant workflow file security-check.yml Variant observed in seven repositories
Variant workflow name Security Check Name used by the smaller workflow variant
Variant commit message Add security check workflow Commit message used by the variant
Current exfiltration IP 193[.]32[.]204[.]199 Plain-HTTP destination for stolen secrets
Variant API endpoint hxxp://193[.]32[.]204[.]199:3000/api/workflow/receive?inj=<id> Per-injection collection endpoint
Historical endpoint bold-dhawan.45-139-104-115[.]plesk[.]page GhostAction infrastructure used in 2025
Historical endpoint carte-avantage[.]com GhostAction infrastructure used in 2025
Historical IP 170[.]39[.]218[.]2 Endpoint used from October–December 2025 and March 2026
Historical domain pattern *.oast[.]fun Interactsh-based endpoint pattern used in late 2025 and early 2026
Suspicious workflow behavior curl -s -X POST -d Command pattern used to send selected GitHub Actions secrets externally

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials appeared first on Cyber Security News.