GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials
GhostAction compromised 500-plus GitHub accounts and planted workflows that steal cloud and AI API credentials.
Socket reports the GhostAction campaign has compromised more than 500 GitHub accounts and injected malicious GitHub Actions workflows into tens of thousands of repositories since October 7, 2026. Workflows such as security-audit.yml run on push, steal Actions secrets, and scan git history for AWS, Anthropic, OpenAI, OpenRouter, GitHub, GitLab, Google, Slack, and SendGrid credentials. Stolen data is sent by cleartext HTTP POST to 193.32.204.199. Successful runs were confirmed, including against kitao/pyxel and uber/athenadriver, but no malicious PyPI or crates.io releases have been observed.
- Campaign hit 500-plus GitHub accounts and tens of thousands of repositories since October 7.
- Malicious security-audit.yml workflows harvest Actions secrets and scan git history for keys.
- Payloads exfiltrate credentials via cleartext HTTP POST to 193.32.204.199.
- Targets included uber/athenadriver and kitao/pyxel publishing tokens.
- No malicious PyPI or crates.io releases have been observed yet.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | crates.io | NAME , creating potential exposure across GitHub, PyPI, and crates.io. The uniform payloads and compressed deployment windows sug |
| url | http://193.32.204[ | s are transmitted together through a cleartext HTTP POST to hxxp://193.32.204[.]199/?c=monami . Socket confirmed successful workflow runs |
Full article633 words · extracted from gbhackers.com · click to collapse
A new GhostAction campaign has expanded to more than 500 compromised GitHub accounts and has injected malicious workflows into tens of thousands of repositories since October 7, 2026.
Socket’s October 9 update describes a credential theft operation targeting GitHub Actions secrets, cloud credentials, and AI service API keys embedded in source code and repository history.
An initially analyzed October 8 burst affected 346 repositories through compromised maintainer accounts henrywoo and kitao.
GhostAction Hackers Compromise 500+ GitHub Accounts
Targets included uber/athenadriver and kitao/pyxel, exposing how contributor permissions can extend an account compromise into organization-owned projects. Socket did not determine how attackers obtained the initial maintainer credentials.
Attackers committed .github/workflows/security-audit.yml directly to repository default branches using messages such as “Add security audit workflow.”
Despite its reassuring name, the workflow harvests credentials. It runs on push events without branch or path restrictions and supports manual execution through workflow_dispatch.
Before deployment, attackers apparently inspected existing workflows to identify referenced Action secrets, then inserted those names into a reusable payload.
In Pyxel, the workflow targeted CARGO_REGISTRY_TOKEN, PERSONAL_ACCESS_TOKEN, PYPI_PASSWORD, and PYPI_USERNAME, creating potential exposure across GitHub, PyPI, and crates.io. The uniform payloads and compressed deployment windows suggest automated enumeration and injection.
The new variant adds a repository scanning stage alongside the established Actions secret theft mechanism.
Using actions/checkout@v4 with fetch-depth: 0, it retrieves history across branches and tags, then examines working-tree files and patch output from git log -p --all. Its history buffer is capped at 200,000 lines.
Thirteen credential patterns cover AWS access identifiers, secret keys and session tokens; Anthropic, OpenAI and OpenRouter API keys; GitHub and GitLab tokens; and Google, Slack and SendGrid credentials.
Historical scanning can uncover secrets removed from current files but still retained in reachable commits. The payload also captures two surrounding lines on either side of AWS access key identifiers.
This context can expose adjacent secret access keys, helping attackers recover usable credential combinations rather than isolated identifiers. Collected data and repository identifiers are transmitted together through a cleartext HTTP POST to hxxp://193.32.204[.]199/?c=monami.
Socket confirmed successful workflow runs in affected repositories, with Pyxel providing the clearest publishing-credential targeting example. However, researchers had observed no malicious PyPI or crates.io releases attributable to this activity.
Defenders should remove injected workflows, review execution logs, revoke compromised account access, and rotate exposed credentials. Response must cover both Actions secrets and committed credentials, including historical exposures.
Socket also recommends auditing package releases, reviewing AWS CloudTrail activity, blocking the exfiltration address, enabling secret scanning with push protection, and inspecting affected forks before enabling Actions. Organization-wide checks should follow account permissions.
| Category | Indicator | Description |
|---|---|---|
| Workflow file path | .github/workflows/security-audit.yml | Malicious workflow file masquerading as a security audit. |
| Workflow file path | .github/workflows/github_actions_security.yml | Alternative malicious workflow file path. |
| Commit message | Add security audit workflow | Commit message associated with malicious workflow injection. |
| Commit message | Update security audit workflow | Commit message associated with malicious workflow updates. |
| Commit message | Add Github Actions Security workflow | Alternative commit message associated with workflow injection. |
| Request body marker | REPO= | Identifies the repository in the exfiltration request body. |
| Request body marker | AKIA_CTX_START | Marks the beginning of collected AWS credential context. |
| Request body marker | AKIA_CTX_END | Marks the end of collected AWS credential context. |
| Network — C2 IP address | 193.32.204[.]199 | Attacker-controlled destination used for credential exfiltration. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.