GitHub Actions Supply Chain Attack Exposes Thousands of Repositories to Credential Theft
Cybersecurity researchers have uncovered details of an ongoing supply chain attack, dubbed GhostAction, that has compromised numerous open-source maintainer accounts on GitHub. The attackers exploited leaked personal access tokens (PATs) to inject malicious workflows, specifically named "Security Audit" or "GitHub Actions Security," into over 340 repositories initially, and subsequently into tens of thousands more. These malicious workflows are designed to exfiltrate sensitive data, including CI/CD secrets, AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens, to a hard-coded IP address.
This incident is a stark reminder for practitioners about the pervasive and evolving nature of supply chain attacks, particularly within the increasingly interconnected DevOps and cloud-native ecosystems. The compromise of high-profile maintainer accounts, such as the author of the `pyxel` game engine and the original author of Uber's `athenadriver`, demonstrates that even trusted sources can become vectors for widespread compromise. The exfiltration of various API keys and credentials highlights the critical importance of securing every link in the software supply chain, from source code repositories to deployment pipelines. The potential impact extends beyond immediate data loss, as compromised credentials can grant attackers access to broader cloud infrastructure and sensitive business applications.
This attack fits into a broader trend of attackers targeting the software supply chain and exploiting identity as the new perimeter. As organizations increasingly adopt cloud-native development practices and leverage CI/CD pipelines, the attack surface expands significantly. The use of automated tools and AI by attackers to accelerate vulnerability exploitation and credential harvesting further exacerbates this challenge. Recent reports have consistently emphasized that identity compromise remains a leading cause of cloud breaches, and that AI infrastructure itself is becoming a significant attack surface. The GhostAction campaign, which first emerged in September 2025, showcases the persistent threat of such attacks and the need for continuous vigilance.
In practice, organizations must prioritize robust secrets management, implementing secure vaults and automated rotation of credentials. Implementing a least-privilege model for all developer accounts and automation tools is crucial to limit the blast radius of any compromise. Furthermore, continuous security scanning within CI/CD pipelines, including static analysis and secret scanning, should be a mandatory practice to detect and prevent the injection of malicious code. Practitioners should also consider implementing advanced threat detection and response mechanisms that can identify anomalous activity within their GitHub repositories and CI/CD environments. Regular audits of GitHub Actions workflows and a strong emphasis on developer security training are also essential to mitigate the risks posed by such sophisticated supply chain attacks. Finally, organizations should have clear incident response plans in place for supply chain compromises, focusing on rapid credential revocation and remediation across all affected systems.
Read original source