New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets
GhostAction hit 346 GitHub repositories, including Uber's, with malicious Actions workflows that stole CI secrets.
Socket said the GhostAction campaign compromised 346 GitHub repositories on October 8 after hijacked maintainer accounts henrywoo and kitao added a fake security-audit GitHub Actions workflow. The workflow posts CI/CD secrets to 193.32.204[.]199 and scans files and full Git history for cloud keys, tokens, and API credentials, including AWS, GitHub, GitLab, Google, Slack, and major AI-provider keys. Targets include Uber's uber/athenadriver and kitao/pyxel, which has more than 18,000 stars. GitGuardian previously tied the campaign to 817 repositories in September 2025 and 772 more through September 2026; Socket had not seen poisoned PyPI or crates.io releases from this wave as of October 9.
- Hijacked accounts henrywoo and kitao added fake security-audit workflows.
- 346 repositories were hit, including Uber athenadriver and kitao/pyxel.
- Workflows posted CI secrets and scanned full Git history for keys.
- Earlier waves hit 817 and 772 repositories and thousands of secrets.
- Socket saw no malicious PyPI or crates.io packages from this wave.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | crates.io | the affected repositories. Stolen PyPI, npm, Docker Hub, or crates.io credentials may allow an attacker to publish a poisoned pac |
Full article848 words · extracted from cybersecuritynews.com · click to collapse
A new GhostAction campaign has compromised 346 GitHub repositories after threat actors used two hijacked maintainer accounts to add a fake “security audit” workflow designed to steal CI/CD secrets, cloud keys, API tokens, and credentials stored in source-code history.
Security firm Socket reported that the October 8 activity affected repositories connected to the GitHub accounts henrywoo and kitao. The targets include Uber’s uber/athenadriver repository and the popular kitao/pyxel project, which has more than 18,000 GitHub stars.
The malicious file, .github/workflows/security-audit.yml, was added through commits named “Add security audit workflow” and “Update security audit workflow.”
The campaign shows how a stolen GitHub maintainer account can expose far more than one personal repository. Once attackers gain write access, they can add a GitHub Actions workflow to every repository the account can modify.
GhostAction Attack
The workflow then runs automatically when developers push code, placing sensitive CI/CD credentials within reach of the attacker. According to Socket’s GhostAction investigation, the malicious workflow sends stolen data through an HTTP POST request to 193.32.204[.]199.
It collects GitHub Actions secrets referenced by existing project workflows, including PyPI passwords, crates.io tokens, GitHub personal access tokens, and package publishing credentials.

The newer GhostAction version also searches the active repository files and the full Git history for hardcoded secrets. This is a major change because developers may remove a key from a current file but leave it exposed in older commits, branches, or tags. The workflow uses fetch-depth: 0, which downloads complete repository history before running searches against it.
Researchers found that the payload looks for AWS access key IDs, AWS secret keys, temporary session tokens, GitHub and GitLab access tokens, Google API keys, Slack tokens, SendGrid credentials, and API keys for OpenAI, Anthropic, and OpenRouter.
It also captures surrounding lines near AWS key IDs, which can help attackers locate the matching secret key required to use an AWS account.
The activity appears highly automated. Socket observed 318 affected repositories under the henrywoo namespace, including 279 forks, along with 27 repositories under kitao and Uber’s athenadriver.
The commits were pushed across short time windows, including inactive repositories that had not received changes for years. This pattern suggests the operator used automated repository discovery rather than selecting projects one by one.

The incident follows earlier GhostAction operations documented by GitGuardian. In September 2025, GitGuardian found the campaign had compromised 817 repositories and stolen at least 3,325 secrets.
A later wave running from late August through September 2026 reached another 772 public repositories and targeted 2,577 secrets.
The older payload focused on GitHub Actions secrets, while this latest version also hunts for credentials embedded in source code and historical commits.
The impact could extend beyond the affected repositories. Stolen PyPI, npm, Docker Hub, or crates.io credentials may allow an attacker to publish a poisoned package update from a trusted project.
This risk is especially serious for popular open-source libraries because a malicious release can reach downstream developers and production systems.
Cyber Security News previously covered how a compromised GitHub Action exfiltrated workflow credentials, showing that CI/CD environments remain a valuable target for supply-chain operators.
As of October 9, Socket said it had not identified malicious packages published to PyPI or crates.io from this latest activity. However, maintainers should treat a successful workflow run as potential credential exposure. Removing the workflow alone is not enough.
Affected teams should revoke GitHub sessions, personal access tokens, OAuth grants, SSH keys, and all secrets named in the malicious workflow. They should also scan the entire Git history, review GitHub Actions run records, inspect package release history, and search network logs for traffic to 193.32.204[.]199.
GitHub secret scanning with push protection, strict branch rules for .github/workflows/ changes, and least-privilege permissions can reduce future exposure. For more background, see our report on the GhostAction supply-chain campaign.
Indicators of Compromise
| IOC Type | Indicator | Description |
|---|---|---|
| Workflow file path | .github/workflows/security-audit.yml | Malicious workflow file path |
| Workflow file path | .github/workflows/github_actions_security.yml | Alternative malicious workflow file path |
| Commit message | Add security audit workflow | Commit message associated with workflow injection |
| Commit message | Update security audit workflow | Commit message associated with workflow injection |
| Commit message | Add Github Actions Security workflow | Alternative commit message associated with workflow injection |
| Request body marker | REPO= | Repository identifier marker in the outbound request body |
| Request body marker | AKIA_CTX_START | Start marker for collected AWS credential context |
| Request body marker | AKIA_CTX_END | End marker for collected AWS credential context |
| C2 IP address | 193.32.204[.]199 | Destination used to receive stolen credentials |
[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.