GhostAction Campaign Escalates, Exfiltrating Cloud and AI Credentials from GitHub Repositories
The GhostAction supply chain attack, first identified in September 2025, has escalated significantly. Recent reports indicate that threat actors have compromised hundreds of GitHub repositories by injecting malicious workflows, primarily named "security-audit.yml" or "github_actions_security.yml." These workflows are designed to exfiltrate sensitive data, including CI/CD secrets, cloud credentials (such as AWS keys, Azure credentials), and AI API tokens (like OpenAI, Anthropic, and OpenRouter keys). The attacks leverage hijacked maintainer accounts to push these workflows, with notable targets including popular projects like `kitao/pyxel` and `uber/athenadriver`.
This resurgence and evolution of GhostAction are critical for the technical community because they demonstrate a persistent and adaptable threat to the software supply chain. Unlike previous iterations that primarily focused on CI/CD secrets, the current campaign actively scans the entire working tree and Git history for a broader range of credentials. This means that even if secrets are removed from active workflows, historical commits could still expose them. The compromise of high-profile maintainer accounts further amplifies the risk, as it allows attackers to inject malicious code into widely used projects, potentially affecting a vast number of downstream users. The direct exfiltration of cloud and AI credentials can lead to unauthorized access to critical infrastructure and sensitive data, with severe financial and reputational consequences.
This trend aligns with the broader, well-established pattern of increasing sophistication in supply chain attacks. As organizations adopt more complex CI/CD pipelines and rely heavily on open-source components, attackers are shifting their focus from direct application vulnerabilities to compromising the development infrastructure itself. The use of stolen credentials to inject malicious code into trusted repositories mirrors tactics seen in other supply chain incidents. The continuous nature of the GhostAction campaign, with attackers reusing and updating workflows and exfiltration endpoints, highlights the need for continuous vigilance and robust security practices beyond one-time audits.
In practice, developers and DevOps teams must take immediate action. First, it is imperative to audit all GitHub repositories for the presence of suspicious workflows, particularly those named "security-audit.yml" or "github_actions_security.yml," with commit dates from late August 2026 onwards. Any identified malicious workflows should be immediately removed. Second, all credentials associated with potentially compromised accounts, including GitHub sessions, Personal Access Tokens (PATs), OAuth grants, SSH keys, and all secrets referenced in the malicious workflows, must be revoked and rotated. Furthermore, organizations should implement stricter branch protection rules for `github/workflows/` directories, enforce least-privilege permissions for GITHUB_TOKEN, and leverage GitHub's secret scanning with push protection to prevent future injections. Regular scanning of Git history for embedded credentials and monitoring network logs for suspicious outbound connections to known attacker infrastructure (e.g., `193.32.204[.]199`) are also crucial.
Read original source