New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A new GhostAction campaign has compromised 346 GitHub repositories after threat actors used two hijacked maintainer accounts to add a fake “security audit” workflow designed to steal CI/CD secrets, cloud keys, API tokens, and credentials stored in source-code history.

Security firm Socket reported that the October 8 activity affected repositories connected to the GitHub accounts henrywoo and kitao.

The targets include Uber’s uber/athenadriver repository and the popular kitao/pyxel project, which has more than 18,000 GitHub stars.

The malicious file, .github/workflows/security-audit.yml, was added through commits named “Add security audit workflow” and “Update security audit workflow.”

The campaign shows how a stolen GitHub maintainer account can expose far more than one personal repository. Once attackers gain write access, they can add a GitHub Actions workflow to every repository the account can modify.

GhostAction Attack

The workflow then runs automatically when developers push code, placing sensitive CI/CD credentials within reach of the attacker. According to Socket’s GhostAction investigation, the malicious workflow sends stolen data through an HTTP POST request to 193.32.204[.]199.

It collects GitHub Actions secrets referenced by existing project workflows, including PyPI passwords, crates.io tokens, GitHub personal access tokens, and package publishing credentials.

Malicious GitHub Actions Workflow (Image Source: Socket)

The newer GhostAction version also searches the active repository files and the full Git history for hardcoded secrets. This is a major change because developers may remove a key from a current file but leave it exposed in older commits, branches, or tags. The workflow uses fetch-depth: 0, which downloads complete repository history before running searches against it.

Researchers found that the payload looks for AWS access key IDs, AWS secret keys, temporary session tokens, GitHub and GitLab access tokens, Google API keys, Slack tokens, SendGrid credentials, and API keys for OpenAI, Anthropic, and OpenRouter.

It also captures surrounding lines near AWS key IDs, which can help attackers locate the matching secret key required to use an AWS account.

The activity appears highly automated. Socket observed 318 affected repositories under the henrywoo namespace, including 279 forks, along with 27 repositories under kitao and Uber’s athenadriver.

The commits were pushed across short time windows, including inactive repositories that had not received changes for years. This pattern suggests the operator used automated repository discovery rather than selecting projects one by one.

AthenaDriver Malicious Workflow Alert (Image Source: Socket)

The incident follows earlier GhostAction operations documented by GitGuardian. In September 2025, GitGuardian found the campaign had compromised 817 repositories and stolen at least 3,325 secrets.

A later wave running from late August through September 2026 reached another 772 public repositories and targeted 2,577 secrets.

The older payload focused on GitHub Actions secrets, while this latest version also hunts for credentials embedded in source code and historical commits.

The impact could extend beyond the affected repositories. Stolen PyPI, npm, Docker Hub, or crates.io credentials may allow an attacker to publish a poisoned package update from a trusted project.

This risk is especially serious for popular open-source libraries because a malicious release can reach downstream developers and production systems.

Cyber Security News previously covered how a compromised GitHub Action exfiltrated workflow credentials, showing that CI/CD environments remain a valuable target for supply-chain operators.

As of October 9, Socket said it had not identified malicious packages published to PyPI or crates.io from this latest activity. However, maintainers should treat a successful workflow run as potential credential exposure. Removing the workflow alone is not enough.

Affected teams should revoke GitHub sessions, personal access tokens, OAuth grants, SSH keys, and all secrets named in the malicious workflow. They should also scan the entire Git history, review GitHub Actions run records, inspect package release history, and search network logs for traffic to 193.32.204[.]199.

GitHub secret scanning with push protection, strict branch rules for .github/workflows/ changes, and least-privilege permissions can reduce future exposure. For more background, see our report on the GhostAction supply-chain campaign.

Indicators of Compromise

IOC Type Indicator Description
Workflow file path .github/workflows/security-audit.yml Malicious workflow file path
Workflow file path .github/workflows/github_actions_security.yml Alternative malicious workflow file path
Commit message Add security audit workflow Commit message associated with workflow injection
Commit message Update security audit workflow Commit message associated with workflow injection
Commit message Add Github Actions Security workflow Alternative commit message associated with workflow injection
Request body marker REPO= Repository identifier marker in the outbound request body
Request body marker AKIA_CTX_START Start marker for collected AWS credential context
Request body marker AKIA_CTX_END End marker for collected AWS credential context
C2 IP address 193.32.204[.]199 Destination used to receive stolen credentials
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets appeared first on Cyber Security News.