Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens
GhostAction abused GitHub Actions workflows to steal SSH keys and cloud credentials from public repositories.
GitGuardian’s GhostAction investigation found 772 public repositories across 373 GitHub users and organizations compromised between August 31 and September 30, 2026. Attackers added workflows such as github_actions_security.yml that posted named secrets, including SSH private keys and cloud credentials, over unencrypted HTTP to 193.32.204.199. Researchers confirmed 26 secrets exfiltrated from 13 repositories while 2,577 were targeted, and only about 16% of affected repositories showed effective cleanup by October 5. The activity continues earlier GhostAction and Shai-Hulud campaigns; one related repository also contained an XMRig miner.