GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials
GhostAction hit 772 GitHub repositories with malicious Actions workflows that stole CI/CD secrets.
GitGuardian reported a GhostAction wave from August 31 to September 30, 2026, that planted malicious GitHub Actions workflows in 772 public repositories and targeted 2,577 secrets across 373 users and organizations. Stolen GitHub access was used to commit workflows that read referenced secrets and exfiltrated them over plain HTTP to 193.32.204.199. Reviewers found 336 successful runs that stole 26 secrets from 13 repositories, and only 16% of affected repositories were cleaned by October 5. A 2025 wave previously hit 817 repositories and at least 3,325 secrets.
- 772 public repositories and 2,577 secrets were targeted from August 31 to September 30, 2026.
- Malicious workflows posted secrets over plain HTTP to 193.32.204.199.
- 336 workflow runs succeeded, stealing 26 secrets from 13 repositories.
- Only 124 of 772 repositories, about 16%, were cleaned by October 5.
- SSH keys, Azure credentials, registry logins, and GitHub tokens were primary targets.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 45-139-104-115.plesk.page | jection collection endpoint Historical endpoint bold-dhawan.45-139-104-115[.]plesk[.]page GhostAction infrastructure used in 2025 Historical endp |
| domain | carte-avantage.com | GhostAction infrastructure used in 2025 Historical endpoint carte-avantage[.]com GhostAction infrastructure used in 2025 Historical IP 170 |
| domain | oast.fun | er–December 2025 and March 2026 Historical domain pattern *.oast[.]fun Interactsh-based endpoint pattern used in late 2025 and e |
| ipv4 | 170.39.218.2 | old-dhawan.45-139-104-115.plesk.page , carte-avantage.com , 170.39.218.2 , and *.oast.fun Interactsh domains. Only 124 of the 772 af |
| ipv4 | 193.32.204.199 | de access. The latest payload sends data over plain HTTP to 193.32.204.199 , replacing older GhostAction infrastructure. A smaller var |
| url | http://193[ | in-HTTP destination for stolen secrets Variant API endpoint hxxp://193[.]32[.]204[.]199:3000/api/workflow/receive?inj=<id> Per-inje |
Full article1,260 words · extracted from cybersecuritynews.com · click to collapse
A new wave of the GhostAction supply chain campaign has compromised 772 public GitHub repositories, using fake GitHub Actions workflow files to steal credentials from CI/CD environments.
The activity ran from August 31 through September 30, 2026, and targeted 2,577 secrets across 373 GitHub users and organizations, including cloud keys, SSH credentials, container registry logins, database passwords, and GitHub tokens.
GitGuardian’s investigation shows that the campaign uses stolen GitHub account access to add malicious workflows under the victim’s own identity.
The malicious files look like normal automation updates, making them easy to miss during a quick code review. In most cases, the actor added a workflow named github_actions_security.yml with the commit message Add Github Actions Security workflow.
The workflow waits for a normal repository push, reads selected GitHub Actions secrets, and sends them to attacker-controlled infrastructure through a curl POST request.
This technique resembles earlier fake CI update credential theft activity, where routine-looking workflow changes were used to access tokens and cloud credentials.
Analysts at GitGuardian identified the latest GhostAction activity after researchers at Cynative independently spotted suspicious commits and contacted the company.
GitGuardian first disclosed GhostAction in September 2025, when the campaign compromised 817 public repositories and collected at least 3,325 secrets.
The latest findings show that it was not a short-lived event: malicious workflows from earlier waves remained in some repositories and were later updated with fresh data-theft endpoints.
GhostAction Supply Chain Campaign Uses Malicious GitHub Actions
GhostAction does not simply collect every variable available to a workflow runner. Instead, the workflow appears to inspect a repository’s existing workflow and configuration history for secret references formatted as ${{ secrets.NAME }}.
It then inserts those exact secret names into the added workflow. This makes the malicious file more focused and allows it to collect credentials that are likely useful for deployment, publishing, cloud management, or source-code access.
The latest payload sends data over plain HTTP to 193.32.204.199, replacing older GhostAction infrastructure. A smaller variant seen in seven repositories used security-check.yml, displayed the workflow name “Security Check,” and used the commit message Add security check workflow.
That variant sent data to an API endpoint containing a unique injection identifier, which suggests the operator may be tracking stolen credentials by repository or workflow instance.
The use of hidden workflow persistence is also consistent with the Shai-Hulud npm supply chain attack, which injected GitHub Actions files to continue collecting secrets after an initial compromise.
GitGuardian recorded three major bursts in the new wave: 143 repositories on August 31; roughly 400 repositories between September 2 and 5, including 294 on September 5 alone; and 103 repositories on September 15. Of 3,669 workflow runs reviewed across 605 repositories, GitHub held most for approval.
Still, 499 ran in 32 repositories, and 336 runs completed successfully, allowing the theft of 26 secrets from 13 repositories. The most commonly targeted values were SSH private keys and deployment-server credentials, accounting for 446 secret references.
Azure credentials were targeted 218 times, while Docker Hub and GitHub Container Registry credentials appeared 142 times.
The workflows also sought database passwords, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, and API tokens for services such as Cloudflare, npm, PyPI, Slack, Telegram, Discord, and AI platforms.
This reflects the growing risk described in trusted developer tooling abuse, where developer systems and build pipelines are used as a route to cloud and source-code access.
GhostAction Campaign Never Fully Stopped
The campaign’s strongest sign of persistence is that, in 92 cases, the actor did not create a new workflow. Instead, they updated an already compromised file using the commit message Update Github Actions Security workflow.
These files had survived from earlier campaign periods and were modified to use the new collection server. Researchers linked the same workflow pattern to older endpoints, including bold-dhawan.45-139-104-115.plesk.page, carte-avantage.com, 170.39.218.2, and *.oast.fun Interactsh domains.
Only 124 of the 772 affected repositories, or 16%, had been effectively cleaned in public commit history as of October 5. That figure matters because a malicious workflow may run again whenever a developer pushes a legitimate commit.
Organizations should therefore treat removal of the workflow as only one part of the response. They must identify how the attacker gained repository write access, revoke the affected GitHub credential, review workflow runs and audit logs, and rotate every secret that may have been available to the runner.
GitHub advises teams to limit each workflow and GITHUB_TOKEN to the minimum permissions required, audit workflow source code and third-party actions, and pin actions to a full commit SHA, which provides an immutable reference.
Organizations should also use environment approval controls for sensitive deployment secrets and closely review newly added or modified files under .github/workflows/. GitHub’s secure-use guidance notes that an exposed secret must be rotated, even when it was masked in logs.
GitGuardian also found a cryptominer in the kuafuai/DevOpsGPT repository, which was later hit by GhostAction. However, the researchers did not attribute both events to the same operator.
The miner used a forged author email, a tailored payload, an XMRig binary disguised as /usr/local/bin/pyworker, and a different operational style, while GhostAction relied on broad, automated GitHub API workflow injection.
The overlap still highlights a key problem: stolen GitHub credentials can be reused by several unrelated threat groups. A compromised maintainer account may be used to collect CI/CD secrets, inject malicious code, publish altered packages, or run cryptomining workloads.
As recent software supply chain threat activity has shown, a single developer identity can become a path into build systems, cloud accounts, package registries, and downstream customer environments.
For defenders, the central lesson is identity control. Teams should not only remove suspicious workflow files and rotate cloud keys; they should revoke exposed GitHub personal access tokens, enforce phishing-resistant multi-factor authentication, require review for workflow changes, apply least-privilege permissions, and monitor outbound network traffic from CI runners.
In GhostAction incidents, leaving the original stolen GitHub credential active could allow the same operator—or another actor holding that credential—to return.
Indicators of compromise (IoCs):-
| IoC Type | Indicator | Context |
|---|---|---|
| Malicious workflow file | github_actions_security.yml | Main GhostAction workflow injected into victim repositories |
| Workflow display name | Github Actions Security | Name used by the principal malicious workflow |
| Commit message | Add Github Actions Security workflow | Common commit message used to add the workflow |
| Commit message | Update Github Actions Security workflow | Used to modify an existing malicious workflow |
| Variant workflow file | security-check.yml | Variant observed in seven repositories |
| Variant workflow name | Security Check | Name used by the smaller workflow variant |
| Variant commit message | Add security check workflow | Commit message used by the variant |
| Current exfiltration IP | 193[.]32[.]204[.]199 | Plain-HTTP destination for stolen secrets |
| Variant API endpoint | hxxp://193[.]32[.]204[.]199:3000/api/workflow/receive?inj=<id> | Per-injection collection endpoint |
| Historical endpoint | bold-dhawan.45-139-104-115[.]plesk[.]page | GhostAction infrastructure used in 2025 |
| Historical endpoint | carte-avantage[.]com | GhostAction infrastructure used in 2025 |
| Historical IP | 170[.]39[.]218[.]2 | Endpoint used from October–December 2025 and March 2026 |
| Historical domain pattern | *.oast[.]fun | Interactsh-based endpoint pattern used in late 2025 and early 2026 |
| Suspicious workflow behavior | curl -s -X POST -d | Command pattern used to send selected GitHub Actions secrets externally |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.