GhostAction Stole CI Secrets via Malicious GitHub Actions
GitGuardian found GhostAction planted malicious GitHub Actions in 772 public repositories, targeting 2,577 secrets and confirming 26 stolen.
GitGuardian’s GhostAction investigation found attackers compromised 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026. Stolen GitHub access was used to commit malicious Actions workflows, including one named github_actions_security.yml, that read referenced secrets and posted them over unencrypted HTTP to 193.32.204.199. Researchers reported 336 successful workflow runs that stole 26 secrets from 13 repositories, while 2,577 secrets were targeted, including SSH private keys, Azure credentials, registry logins, and GitHub tokens. By October 5, only 124 of 772 repositories—about 16%—showed cleanup. The campaign continues earlier GhostAction activity and overlaps Shai-Hulud credential harvesting; a 2025 GhostAction wave hit 817 repositories and at least 3,325 secrets, and one related repository also contained an XMRig miner. The two reports agree on the core counts and do not contradict each other.
- 772 public repositories across 373 GitHub users and organizations were compromised between August 31 and September 30, 2026.
- Stolen GitHub access was used to commit malicious Actions workflows, including github_actions_security.yml, that posted secrets over unencrypted HTTP to 193.32.204.199.
- 336 successful workflow runs stole 26 secrets from 13 repositories; 2,577 secrets were targeted.
- Targeted secrets included SSH private keys, Azure credentials, registry logins, and GitHub tokens.
- Only 124 of 772 repositories, about 16%, were cleaned by October 5, 2026.
- A 2025 GhostAction wave previously hit 817 repositories and at least 3,325 secrets.
- The activity continues earlier GhostAction waves and overlaps Shai-Hulud; one related repository contained an XMRig miner.
Coverage timelineoldest first · each row is one article
- · 17h agoHackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens
GBHackers· 74
GhostAction abused GitHub Actions workflows to steal SSH keys and cloud credentials from public repositories.
- · 11h agoGhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials
Cyber Security News· 78
GhostAction hit 772 GitHub repositories with malicious Actions workflows that stole CI/CD secrets.