GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials
GhostAction hit 772 GitHub repositories with malicious Actions workflows that stole CI/CD secrets.
GitGuardian reported a GhostAction wave from August 31 to September 30, 2026, that planted malicious GitHub Actions workflows in 772 public repositories and targeted 2,577 secrets across 373 users and organizations. Stolen GitHub access was used to commit workflows that read referenced secrets and exfiltrated them over plain HTTP to 193.32.204.199. Reviewers found 336 successful runs that stole 26 secrets from 13 repositories, and only 16% of affected repositories were cleaned by October 5. A 2025 wave previously hit 817 repositories and at least 3,325 secrets.