GhostAction Attack Steals Secrets from GitHub Repositories
Key Takeaways A new GhostAction campaign has compromised 346 GitHub repositories by leveraging hijacked maintainer accounts. Attackers injected a deceptive “security audit” workflow to...
Key Takeaways
- A new GhostAction campaign has compromised 346 GitHub repositories by leveraging hijacked maintainer accounts.
- Attackers injected a deceptive “security audit” workflow to steal CI/CD secrets, cloud keys, API tokens, and credentials from both active files and Git history.
- The compromised accounts, “henrywoo” and “kitao,” affected prominent projects including Uber’s uber/athenadriver and the popular kitao/pyxel.
- This latest iteration of GhostAction significantly expands its reach by actively searching full Git history for hardcoded secrets, not just active workflow secrets.
- Defenders must revoke all potentially exposed credentials, audit Git history, and implement strict security measures to mitigate ongoing risks.
A sophisticated GhostAction campaign has infiltrated 346 GitHub repositories, with threat actors exploiting two compromised maintainer accounts to introduce a fraudulent “security audit” workflow. This malicious workflow was designed to exfiltrate critical CI/CD secrets, cloud keys, API tokens, and various credentials, including those embedded deep within source-code history.
Table Of Content
Security firm Socket reported that this activity, observed on October 8, impacted repositories linked to the GitHub profiles “henrywoo” and “kitao.” Among the high-profile targets were Uber’s uber/athenadriver repository and the widely recognized kitao/pyxel project, which boasts over 18,000 GitHub stars.
The attackers injected the malicious file, named .github/workflows/security-audit.yml, through commits titled “Add security audit workflow” and “Update security audit workflow.”
This incident underscores a critical vulnerability: a stolen GitHub maintainer account can compromise a vast network of repositories, not just personal projects. Once write access is secured, attackers can deploy a GitHub Actions workflow across every repository the account has permission to modify.
GhostAction Attack Mechanics
The injected workflow automatically executes whenever developers push code, thereby exposing sensitive CI/CD credentials to the attackers. According to Socket’s GhostAction investigation, the compromised data is then transmitted via an HTTP POST request to the IP address 193.32.204[.]199.
This workflow systematically gathers GitHub Actions secrets referenced by existing project workflows. This includes, but is not limited to, PyPI passwords, crates.io tokens, GitHub personal access tokens, and credentials used for package publishing.
A notable enhancement in this newer GhostAction variant is its capability to scan active repository files and the complete Git history for hardcoded secrets. This represents a significant escalation, as developers might remove a key from a current file, inadvertently leaving it exposed in older commits, branches, or tags. The workflow achieves this by utilizing fetch-depth: 0, which ensures the entire repository history is downloaded before conducting its searches.
Researchers discovered that the payload actively seeks a wide array of sensitive information, including AWS access key IDs, AWS secret keys, temporary session tokens, GitHub and GitLab access tokens, Google API keys, Slack tokens, SendGrid credentials, and API keys for platforms like OpenAI, Anthropic, and OpenRouter.
Furthermore, it collects surrounding lines near AWS key IDs. This contextual information is crucial for attackers, as it aids in identifying the corresponding secret key needed to exploit an AWS account.
Automated Campaign Execution
The operation appears highly automated. Socket observed 318 affected repositories under the “henrywoo” namespace, comprising 279 forks, along with 27 repositories under “kitao” and Uber’s “athenadriver.”
The commits were pushed within short timeframes, even impacting inactive repositories that had not seen updates for years. This pattern strongly suggests the use of automated repository discovery by the operators, rather than a manual selection of projects.
This incident follows previous GhostAction operations documented by GitGuardian. In September 2025, an earlier campaign compromised 817 repositories and stole at least 3,325 secrets. A subsequent wave, spanning from late August through September 2026, targeted another 772 public repositories and 2,577 secrets.
The key distinction in this latest version is its broadened scope: older payloads primarily focused on GitHub Actions secrets, whereas this iteration actively seeks credentials embedded within source code and historical commits.
Potential Supply Chain Impact
The repercussions of this compromise could extend beyond the directly affected repositories. Stolen credentials for platforms like PyPI, npm, Docker Hub, or crates.io could enable attackers to publish malicious package updates under the guise of trusted projects. This risk is particularly severe for popular open-source libraries, as a poisoned release can propagate widely, reaching downstream developers and critical production systems.
As of October 9, Socket indicated that no malicious packages had been identified on PyPI or crates.io stemming from this recent activity. However, maintainers should treat any successful workflow run as a potential credential exposure. Simply removing the malicious workflow is insufficient.
What You Should Do
- Revoke Credentials: Immediately revoke all GitHub sessions, personal access tokens (PATs), OAuth grants, SSH keys, and any secrets explicitly named or implicated in the malicious workflow.
- Audit Git History: Conduct a comprehensive scan of the entire Git history for hardcoded secrets that may have been exposed.
- Review GitHub Actions: Examine GitHub Actions run records for any suspicious activity or unexpected workflow executions.
- Inspect Package Releases: Review the release history of any packages associated with the compromised repositories for unauthorized or malicious updates.
- Network Log Analysis: Search network logs for any outbound traffic to the command-and-control (C2) IP address 193.32.204[.]199.
- Implement Proactive Security: Utilize GitHub secret scanning with push protection, enforce strict branch rules for changes to
.github/workflows/, and adhere to the principle of least privilege for all repository access.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.