Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Teams to Warn Users of Malicious QR Code Links
October 10, 2026
Critical AWS Bug Exposes AI Agents to Credential Theft
October 10, 2026
REA Tool Links AI to Ghidra, IDA Pro for Reverse Engineering
October 10, 2026
Home/CyberSecurity News/GhostAction Attack Steals Secrets from GitHub Repositories
CyberSecurity News

GhostAction Attack Steals Secrets from GitHub Repositories

Key Takeaways A new GhostAction campaign has compromised 346 GitHub repositories by leveraging hijacked maintainer accounts. Attackers injected a deceptive “security audit” workflow to...

Marcus Rodriguez
Marcus Rodriguez
October 9, 2026 4 Min Read
23 0

Key Takeaways

  • A new GhostAction campaign has compromised 346 GitHub repositories by leveraging hijacked maintainer accounts.
  • Attackers injected a deceptive “security audit” workflow to steal CI/CD secrets, cloud keys, API tokens, and credentials from both active files and Git history.
  • The compromised accounts, “henrywoo” and “kitao,” affected prominent projects including Uber’s uber/athenadriver and the popular kitao/pyxel.
  • This latest iteration of GhostAction significantly expands its reach by actively searching full Git history for hardcoded secrets, not just active workflow secrets.
  • Defenders must revoke all potentially exposed credentials, audit Git history, and implement strict security measures to mitigate ongoing risks.

A sophisticated GhostAction campaign has infiltrated 346 GitHub repositories, with threat actors exploiting two compromised maintainer accounts to introduce a fraudulent “security audit” workflow. This malicious workflow was designed to exfiltrate critical CI/CD secrets, cloud keys, API tokens, and various credentials, including those embedded deep within source-code history.

Table Of Content

  • Key Takeaways
  • GhostAction Attack Mechanics
  • Automated Campaign Execution
  • Potential Supply Chain Impact
  • What You Should Do

Security firm Socket reported that this activity, observed on October 8, impacted repositories linked to the GitHub profiles “henrywoo” and “kitao.” Among the high-profile targets were Uber’s uber/athenadriver repository and the widely recognized kitao/pyxel project, which boasts over 18,000 GitHub stars.

The attackers injected the malicious file, named .github/workflows/security-audit.yml, through commits titled “Add security audit workflow” and “Update security audit workflow.”

This incident underscores a critical vulnerability: a stolen GitHub maintainer account can compromise a vast network of repositories, not just personal projects. Once write access is secured, attackers can deploy a GitHub Actions workflow across every repository the account has permission to modify.

GhostAction Attack Mechanics

The injected workflow automatically executes whenever developers push code, thereby exposing sensitive CI/CD credentials to the attackers. According to Socket’s GhostAction investigation, the compromised data is then transmitted via an HTTP POST request to the IP address 193.32.204[.]199.

This workflow systematically gathers GitHub Actions secrets referenced by existing project workflows. This includes, but is not limited to, PyPI passwords, crates.io tokens, GitHub personal access tokens, and credentials used for package publishing.

A notable enhancement in this newer GhostAction variant is its capability to scan active repository files and the complete Git history for hardcoded secrets. This represents a significant escalation, as developers might remove a key from a current file, inadvertently leaving it exposed in older commits, branches, or tags. The workflow achieves this by utilizing fetch-depth: 0, which ensures the entire repository history is downloaded before conducting its searches.

Researchers discovered that the payload actively seeks a wide array of sensitive information, including AWS access key IDs, AWS secret keys, temporary session tokens, GitHub and GitLab access tokens, Google API keys, Slack tokens, SendGrid credentials, and API keys for platforms like OpenAI, Anthropic, and OpenRouter.

Furthermore, it collects surrounding lines near AWS key IDs. This contextual information is crucial for attackers, as it aids in identifying the corresponding secret key needed to exploit an AWS account.

Automated Campaign Execution

The operation appears highly automated. Socket observed 318 affected repositories under the “henrywoo” namespace, comprising 279 forks, along with 27 repositories under “kitao” and Uber’s “athenadriver.”

The commits were pushed within short timeframes, even impacting inactive repositories that had not seen updates for years. This pattern strongly suggests the use of automated repository discovery by the operators, rather than a manual selection of projects.

This incident follows previous GhostAction operations documented by GitGuardian. In September 2025, an earlier campaign compromised 817 repositories and stole at least 3,325 secrets. A subsequent wave, spanning from late August through September 2026, targeted another 772 public repositories and 2,577 secrets.

The key distinction in this latest version is its broadened scope: older payloads primarily focused on GitHub Actions secrets, whereas this iteration actively seeks credentials embedded within source code and historical commits.

Potential Supply Chain Impact

The repercussions of this compromise could extend beyond the directly affected repositories. Stolen credentials for platforms like PyPI, npm, Docker Hub, or crates.io could enable attackers to publish malicious package updates under the guise of trusted projects. This risk is particularly severe for popular open-source libraries, as a poisoned release can propagate widely, reaching downstream developers and critical production systems.

As of October 9, Socket indicated that no malicious packages had been identified on PyPI or crates.io stemming from this recent activity. However, maintainers should treat any successful workflow run as a potential credential exposure. Simply removing the malicious workflow is insufficient.

What You Should Do

  • Revoke Credentials: Immediately revoke all GitHub sessions, personal access tokens (PATs), OAuth grants, SSH keys, and any secrets explicitly named or implicated in the malicious workflow.
  • Audit Git History: Conduct a comprehensive scan of the entire Git history for hardcoded secrets that may have been exposed.
  • Review GitHub Actions: Examine GitHub Actions run records for any suspicious activity or unexpected workflow executions.
  • Inspect Package Releases: Review the release history of any packages associated with the compromised repositories for unauthorized or malicious updates.
  • Network Log Analysis: Search network logs for any outbound traffic to the command-and-control (C2) IP address 193.32.204[.]199.
  • Implement Proactive Security: Utilize GitHub secret scanning with push protection, enforce strict branch rules for changes to .github/workflows/, and adhere to the principle of least privilege for all repository access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Vulnerability in Terraform Exposes Developer Systems to Malware

Next Post

Critical AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GhostAction Attack Steals Secrets from GitHub Repositories
October 9, 2026
Critical Vulnerability in Terraform Exposes Developer Systems to Malware
October 9, 2026
Cisco Talos: AI Autonomous Agents Could Transform Pentests Into Covert Red Team Operations
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us