→ Back to Home
GitHub Actions

GhostAction Returns: Supply Chain Attack on GitHub Actions Resurfaces, Compromising Hundreds of Repositories

The GhostAction supply chain attack, which first surfaced in September 2025, has made a significant return, impacting 772 public GitHub repositories belonging to 373 users and organizations between August 31st and September 30th, 2026. This resurgence saw the malicious workflow injected into repositories, primarily to steal credentials from CI/CD pipelines. The attack technique remains largely consistent with the 2025 campaign: a workflow file named `github_actions_security.yml` is injected, containing a script that scrapes for `secrets.NAME` references within the repository's legitimate workflows. These identified secrets are then exfiltrated via a `curl POST` request to an attacker-controlled server. A notable change in this wave is the exfiltration endpoint, which now uses a bare IP address, suggesting a backend system for tracking stolen secrets. This re-emergence is a stark reminder for practitioners that supply chain attacks are not one-off events but evolving, persistent threats. The fact that the same techniques are being reused, likely with previously compromised credentials, underscores the importance of a proactive security posture. Developers and organizations relying on GitHub Actions must understand that their CI/CD pipelines are prime targets for credential theft and intellectual property exfiltration. The widespread impact, affecting hundreds of repositories, demonstrates the attacker's ability to scale these operations, making it a significant concern for anyone using GitHub for their development workflows. This isn't merely an announcement; it's a call to action for heightened security awareness and implementation. This incident fits squarely within the broader trend of increasing software supply chain attacks, a critical concern in modern DevOps and cloud-native environments. The `tj-actions/changed-files` supply chain attack in March 2025, which compromised over 23,000 repositories, and the Shai-Hulud npm worm, which backdoored hundreds of npm packages and registered victim hosts as rogue GitHub Actions self-hosted runners, are just a few examples of this escalating threat landscape. These attacks exploit the interconnected nature of modern software development, where a compromise in one component can have a cascading effect across numerous projects and organizations. The GitHub Actions 2026 Security Roadmap, with features like workflow-level dependency locking, workflow execution protections, and scoped secrets, aims to address these structural vulnerabilities by making CI/CD more deterministic, governable, and observable. In practice, practitioners should immediately audit their GitHub Actions workflows for any unauthorized changes or suspicious files, particularly those named `github_actions_security.yml`. It is crucial to review all secrets referenced in workflows and consider rotating them, especially if there's any doubt about their compromise. Implementing stricter access controls and adhering to the principle of least privilege for `GITHUB_TOKEN` permissions is paramount. Furthermore, organizations should prioritize the adoption of GitHub's security roadmap features as they become generally available, such as workflow dependency locking to ensure deterministic execution and scoped secrets for improved governance. Regularly reviewing audit logs for unusual activity and integrating third-party security scanning tools for continuous monitoring of GitHub Actions environments are also essential steps to mitigate the risk of such persistent supply chain attacks.
#github actions#supply chain attack#security#devops#credentials#ci/cd
Read original source