The open-source software ecosystem is currently facing a formidable and persistent threat known as GhostAction. Cybersecurity researchers have recently disclosed that this massive supply chain attack campaign, which first surfaced in September 2025, has entered an aggressive new phase. By compromising high-profile developer accounts, the threat actors behind GhostAction are systematically injecting malicious GitHub workflows into hundreds of repositories, effectively turning trusted development environments into automated credential-harvesting machines.
As of October 2026, the scale of the operation has reached alarming proportions. Security firm Socket has identified over 500 compromised GitHub accounts, with the malicious workflows infiltrating tens of thousands of repositories. This campaign represents a significant escalation in the use of automated CI/CD (Continuous Integration/Continuous Deployment) pipelines as a vector for large-scale data exfiltration.
Chronology of the Escalation
The GhostAction campaign is characterized by its surgical precision and rapid execution. The most recent activity, documented by researchers at StepSecurity, highlights how the attackers leverage the authority of well-known maintainers to distribute malicious code.
The October 2026 Surge
On October 7, 2026, the campaign accelerated significantly. The attackers gained unauthorized access to the account of Takashi Kitao, the author of the widely used game engine pyxel, which boasts over 18,400 stars on GitHub. Utilizing this trusted account, the threat actors pushed a malicious workflow to 27 repositories beginning at 13:20 UTC.

The momentum continued just eight hours later when the attackers pivoted to the account of Henry Wu (henrywoo), the original author of Uber’s athenadriver. In a highly coordinated 16-minute window between 21:10 and 21:26 UTC, the attackers injected the same malicious workflow into 318 additional repositories.
Historical Context: The September 2026 Offensive
This recent activity is an evolution of a broader campaign that gained momentum throughout September 2026. GitGuardian reports that between August 31 and September 30, 2026, the GhostAction campaign successfully targeted 772 public repositories across 373 unique GitHub users and organizations. During this period, the attackers focused on harvesting 2,577 specific secrets, ranging from SSH private keys to cloud infrastructure credentials.
Anatomy of the Attack: The Malicious Workflow
The GhostAction campaign relies on the injection of seemingly benign workflow files, typically named security-audit.yml or github_actions_security.yml. These files are designed to appear as standard automated security checks, a common practice in modern DevOps.
Operational Mechanics
Once a repository is compromised, the workflow is configured to trigger on workflow_dispatch and any unfiltered push event across all branches and tags. By setting fetch-depth: 0, the attacker ensures that the workflow gains access to the entire history of the repository, not just the latest commit. The "Audit" step of the workflow executes four critical actions:

- Environment Discovery: The script scans the repository for environment variables and secrets defined within the GitHub Actions settings.
- Credential Mining: It traverses the entire
githistory to extract hard-coded secrets, including API keys (AWS, Anthropic, OpenAI, OpenRouter), cloud provider credentials (Azure, Google Cloud, Firebase), and registry tokens (npm, PyPI, DockerHub). - Data Exfiltration: The stolen data is transmitted to an external server hosted at the IP address
193.32.204[.]199. Crucially, this exfiltration occurs over plain HTTP, bypassing encrypted channels to simplify the connection process for the attacker. - Persistent Mapping: Even in repositories where no secrets are found, the script sends a repository identifier to the command-and-control (C2) server. This allows the threat actors to maintain a comprehensive map of all reachable execution contexts within the victim’s GitHub environment.
Supporting Data and The Scope of Impact
The reach of GhostAction extends far beyond simple credential theft. The campaign has demonstrated a capacity for secondary malicious payloads. For instance, on August 30, 2026, researchers observed an attempt to embed an XMRig cryptocurrency miner directly into the Docker image of the kuafuai/DevOpsGPT repository.
Categories of Stolen Assets
The breadth of the data compromised by GhostAction is staggering. Based on industry reports, the following categories of sensitive information are at risk:
- Cloud Infrastructure: AWS Access Keys, Azure Service Principal credentials, Google Cloud and Firebase keys.
- Development & Publishing: npm, PyPI, and GitHub/GitLab tokens.
- Communication & Bot Tokens: Credentials for Telegram, Slack, and Discord bots.
- Container Security: DockerHub and GitHub Container Registry (GHCR) credentials.
- AI Ecosystem: Keys associated with OpenAI, Anthropic, and OpenRouter.
As of early October 2026, more than 3,325 unique secrets had been confirmed as exfiltrated, though researchers believe the actual number is likely significantly higher given the volume of repositories currently under observation.
Implications for the Open-Source Community
The implications of the GhostAction campaign are profound, particularly regarding the trust models inherent in open-source development.

The Danger of Forked Repositories
One of the most insidious aspects of this attack is its impact on forks. Socket researchers have noted that the 279 forks in the henrywoo namespace each contain the malicious workflow. If a user synchronizes their fork with the compromised upstream repository, they inadvertently pull the malicious workflow into their own environment. This creates a "downstream contagion" effect, where the infection propagates through the ecosystem even if the original maintainer eventually remediates their account.
Private Repository Exposure
Perhaps the most concerning discovery is the risk to private repositories. While many developers focus on the security of their public code, the GhostAction workflow is designed to execute within any repository where it is present. Private repositories often contain the "crown jewels"—production database credentials, proprietary signing keys, and internal service tokens. Because private forks often inherit the settings of the upstream repository, they become primary targets for credential exfiltration.
Official Guidance and Mitigation
Cybersecurity experts, including the teams at StepSecurity and GitGuardian, strongly advise all developers to treat their GitHub environments as potentially compromised if they have been active in the affected repositories since August 31, 2026.
Recommended Remediation Steps
- Audit Workflows: Immediately search all repositories for
security-audit.ymlorgithub_actions_security.yml. If found, delete the files across all branches and tags. - Revoke and Rotate: Assume that any secret stored in GitHub Actions, or any secret present in the
githistory of an affected repository, has been stolen. Revoke these credentials immediately and rotate them with new, securely generated keys. - Inspect Forks: Check all forks and downstream mirrors of your repositories. If you maintain a fork of a project that was compromised, you must manually scrub the malicious workflow from your environment.
- Strengthen Access Control: Enable multi-factor authentication (MFA) on all developer accounts and implement strict branch protection rules to prevent unauthorized workflows from being merged without peer review.
- Monitor Logs: Review GitHub Actions execution logs for any suspicious network activity, particularly outbound connections to unknown or non-HTTPS endpoints.
Conclusion
The GhostAction campaign serves as a sobering reminder of the fragility of the software supply chain. By exploiting the inherent trust in CI/CD automation, the attackers have successfully bypassed traditional security perimeters. As the open-source community continues to grapple with the fallout of these compromises, the focus must shift toward more resilient development practices—prioritizing the security of automated workflows with the same rigor applied to production code. Until then, vigilance remains the only effective defense against the "ghosts" in the machine.








