VYPR
breachPublished Oct 8, 2026· 1 source

GhostAction Campaign Leverages Malicious GitHub Actions to Steal CI/CD Credentials

The GhostAction supply chain campaign has compromised 772 public GitHub repositories by injecting malicious GitHub Actions workflow files to steal CI/CD credentials.

A sophisticated supply chain campaign dubbed GhostAction has resurfaced, compromising an estimated 772 public GitHub repositories between August 31 and September 30, 2026. Attackers are exploiting GitHub Actions, a popular CI/CD automation tool, by injecting malicious workflow files designed to exfiltrate sensitive credentials. The campaign targets cloud keys, SSH credentials, container registry logins, database passwords, and various tokens, posing a significant risk to software development pipelines.

The modus operandi involves attackers gaining access to GitHub accounts and then adding seemingly innocuous workflow files under the victim's own identity. These malicious files, often named github_actions_security.yml or security-check.yml with commit messages like "Add Github Actions Security workflow," are designed to blend in with legitimate automation updates. Once deployed, these workflows wait for a repository push, identify and read specific GitHub Actions secrets, and then transmit this sensitive data to attacker-controlled infrastructure via curl POST requests.

This latest wave of GhostAction activity builds upon previous iterations. GitGuardian, which first disclosed the campaign in September 2025, noted that malicious workflows from earlier periods remained active in some repositories and were updated with new data-exfiltration endpoints. The campaign's persistence is further evidenced by instances where attackers modified existing compromised files rather than creating new ones, indicating a sustained effort to maintain access and collect credentials.

GhostAction's targeting is precise; it doesn't indiscriminately collect all available secrets. Instead, the malicious workflows inspect a repository's history for secret references formatted as ${{ secrets.NAME }} and then incorporate those exact names into the new workflow. This focused approach ensures the exfiltrated credentials are likely to be valuable for deployment, publishing, cloud management, or source-code access.

The campaign's infrastructure has also evolved, with the latest payload sending data over plain HTTP to 193.32.204.199. A smaller variant observed in seven repositories utilized a security-check.yml workflow and sent data to an API endpoint with a unique injection identifier, suggesting the operator may be tracking stolen credentials on a granular level.

Analysis of workflow runs revealed that while GitHub often held malicious workflows for approval, a significant number still executed, leading to the successful theft of secrets. The most commonly targeted credentials included SSH private keys, deployment server credentials, Azure credentials, and Docker Hub/GitHub Container Registry credentials. This highlights the growing trend of attackers targeting developer tooling to gain access to cloud environments and source code.

Organizations affected by GhostAction are urged to take comprehensive remediation steps beyond simply removing the malicious workflow. This includes identifying the initial point of compromise, revoking affected GitHub credentials, auditing workflow runs and logs, and rotating all potentially exposed secrets. GitHub recommends best practices such as limiting workflow permissions, auditing workflow source code, pinning actions to specific commit SHAs, and utilizing environment approval controls for sensitive secrets.

The persistence and evolving tactics of the GhostAction campaign underscore the persistent threat of supply chain attacks targeting CI/CD pipelines. The campaign's ability to remain active and adapt its methods serves as a stark reminder for developers and security teams to maintain vigilance and implement robust security measures to protect their development environments.

Synthesized by Vypr AI