Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

GhostAction Supply Chain Campaign Escalates with Hundreds of Open-Source Repository Compromises

Cahyo Dewo, October 10, 2026

The cybersecurity landscape is currently grappling with a significant resurgence of the GhostAction supply chain attack, a sophisticated credential-theft campaign that has successfully compromised high-profile developer accounts to infiltrate over 340 open-source repositories. By hijacking the GitHub credentials of respected maintainers, threat actors have automated the injection of malicious CI/CD workflows, turning trusted automated systems into conduits for mass data exfiltration.

This latest wave of activity, identified by researchers at StepSecurity and Socket, marks a critical evolution in the GhostAction campaign, which first emerged in September 2025. The scope of the current breach is expansive, with investigators identifying more than 500 GitHub accounts that have committed malicious workflows to tens of thousands of repositories since October 7, 2026. The campaign underscores a growing trend in software supply chain vulnerabilities, where attackers exploit the inherent trust placed in CI/CD automation to bypass traditional security perimeters.

Chronology of the Recent Infiltration

The precision of the latest attacks suggests a highly coordinated effort to maximize exposure within a minimal timeframe. On October 9, 2026, security researchers mapped the timeline of the most recent breaches, highlighting the efficiency with which the attackers operate.

The first identified intrusion involved the account of Takashi Kitao, the creator of the popular game engine "pyxel," which boasts over 18,400 stars on GitHub. At 13:20 UTC, the threat actor utilized Kitao’s compromised account to push a malicious workflow into 27 separate repositories. The activity did not cease there; eight hours later, the attackers pivoted to the account of Henry Wu, the original author of Uber’s "athenadriver." In a rapid-fire operation spanning just 16 minutes—from 21:10 to 21:26 UTC—the attackers successfully pushed the same malicious workflow to 318 repositories under Wu’s management.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

This rapid, automated deployment of malicious files indicates that the attackers possess a streamlined infrastructure for credential harvesting and repository injection, allowing them to scale their operations across disparate ecosystems without manual intervention for each target.

Mechanics of the GhostAction Workflow

The core of the GhostAction campaign lies in its simplicity and effectiveness. The attackers inject a workflow file—variously titled "security-audit.yml" or "github_actions_security.yml"—into the target repository. Despite the benign-sounding names, these files are engineered to perform covert data exfiltration.

Once the workflow is triggered via a workflow_dispatch event or an unfiltered push to any branch or tag, the script executes an "Audit" function. This function performs a comprehensive sweep of the repository, including the entire git history, to identify and extract sensitive information. The workflow is designed to exfiltrate data to a hard-coded IP address (193.32.204.199) using plain HTTP. By relying on unencrypted communication, the attackers ensure that the data transit is lightweight, though it remains highly visible to network traffic analysis.

The cache of stolen data is significant. The workflows are programmed to scrape GitHub Actions secrets, including CI/CD configuration tokens, cloud infrastructure keys (such as AWS), AI provider credentials (Anthropic, OpenAI, OpenRouter), and tokens for various developer platforms like GitLab, npm, PyPI, and DockerHub.

Historical Context and Evolution of the Campaign

The GhostAction campaign first drew the attention of the security community in September 2025. During that initial phase, researchers identified 817 repositories across 327 users that had been compromised, resulting in the loss of 3,325 unique secrets.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Between August 31 and September 30, 2026, the campaign saw a renewed surge. GitGuardian reports that the attackers targeted 772 public repositories belonging to 373 distinct GitHub users and organizations. The variety of stolen credentials during this period was vast, encompassing everything from SSH private keys and Azure credentials to Telegram and Discord bot tokens.

A particularly concerning development observed on August 30, 2026, was the modification of the "kuafuai/DevOpsGPT" repository. In this instance, the attackers did not merely steal credentials; they embedded an XMRig cryptocurrency miner within the project’s Docker image. While there is no evidence that the attackers have yet published malicious packages—which would represent a "Tier 1" supply chain attack—the capability to modify build artifacts demonstrates a dangerous potential for future large-scale software distribution attacks.

Broader Implications for the Open-Source Ecosystem

The implications of the GhostAction campaign are profound, particularly for enterprises that rely on open-source dependencies. Because these workflows are committed directly into the source code, they are often propagated downstream to any organization that forks the affected repositories or relies on them for internal development.

Socket researchers have pointed out that private forks and internal mirrors are uniquely vulnerable. In many cases, developers store their own private production secrets within these repositories. When a maintainer’s account is compromised and a malicious workflow is pushed, it effectively turns those downstream private repositories into data-collection points for the attacker.

Furthermore, the "map of reachable execution contexts" held by the attackers is a strategic asset. By tracking which repositories run the malicious workflow, the threat actors can identify which targets are most likely to yield high-value credentials, allowing them to refine their future targeting strategies.

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Mitigation and Remediation Strategies

Security experts emphasize that the mere presence of the "security-audit.yml" file should be treated as a full compromise of the affected environment. The recommended response for repository owners and organizations is comprehensive and immediate:

  1. Credential Rotation: All secrets stored in the affected repository—including API keys, tokens, and SSH keys—must be considered compromised and should be revoked and regenerated immediately.
  2. Workflow Removal: The malicious YAML files must be purged from all branches, tags, and commit histories.
  3. Audit of Forks: Because the attack propagates through downstream forks, maintainers must alert the community and check for the presence of these workflows in any existing forks of their projects.
  4. Enforcement of MFA: While the exact method of credential theft remains under investigation, the widespread compromise of developer accounts highlights the necessity for hardware-based multi-factor authentication (MFA) and the use of scoped personal access tokens (PATs) with limited permissions.

Expert Analysis and Future Outlook

The persistence of GhostAction reflects a shift in the threat landscape where the "human-in-the-loop" (the maintainer) is treated as the weakest link in the supply chain. By compromising the maintainer’s GitHub identity, the attackers leverage the inherent trust that users have in updates and commits originating from established accounts.

Industry analysts suggest that this campaign will force a reassessment of how CI/CD pipelines are secured. Current industry best practices often focus on securing the build server, but GhostAction demonstrates that the repository itself—and the permissions assigned to the Actions that run within it—requires a more granular approach. Moving forward, the implementation of "Least Privilege" for GitHub Actions, where workflows are restricted from accessing secrets unless absolutely necessary, may become a standard requirement for open-source project management.

As of October 2026, the situation remains fluid. Both GitHub and the affected maintainers are working to mitigate the damage, but the sheer scale of the automated injection makes total remediation a lengthy process. For the global developer community, the GhostAction campaign serves as a stark reminder that in an era of automated software supply chains, the integrity of a single account can affect the security of thousands of downstream projects. Vigilance, continuous monitoring of repository activity, and the rapid rotation of secrets remain the most effective defenses against this evolving threat.

Cybersecurity & Digital Privacy campaignchaincompromisesCybercrimeescalatesghostactionHackinghundredsopenPrivacyrepositorySecuritysourcesupply

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes