Threat reportSupply ChainTL-2026-3157

GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories

highACTIVE

GhostAction: Credential-Stealing GitHub Actions Workflows (TL-2026-3157), also tracked as GhostAction, is a high-severity supply-chain compromise, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects GitHub GitHub Actions workflows in repositories of compromised, maps to 15 MITRE ATT&CK techniques (T1027.002, T1036.005, T1041), and is covered by 9 detection rules and 38 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
38Indicators of compromise

Key facts for TL-2026-3157

Threat ID
TL-2026-3157
Also known as
GhostAction, GhostAction Returns
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, software-development, open-source
Target regions
Global
Detection rules
9
Indicators of compromise
38
Updates
2026-10-10 · 3 updates · revalidated 3× · latest source

Malware and tooling in GhostAction: Credential-Stealing GitHub Actions Workflows

Malware and tooling: xmrig

How GhostAction: Credential-Stealing GitHub Actions Workflows works

Malicious GitHub Actions workflows disguised as security audits (security-audit.yml, github_actions_security.yml) were committed to default branches through compromised maintainer GitHub accounts. They exfiltrate CI/CD secrets, and in the October 2026 variant also committed credentials from the working tree and full git history, over plain HTTP to the hard-coded IP 193.32.204.199.

GhostAction is a GitHub Actions supply-chain credential-theft campaign first documented in September 2025 (GitGuardian: about 817 repositories, 327 users, 3,325 secrets exfiltrated) and resurfacing from 2026-08-31. The operator obtains a maintainer's GitHub credential through a means not established in the sources, then commits a workflow that looks like a security audit directly to the default branch, bypassing pull-request review. Commit messages seen include 'Add security audit workflow', 'Update security audit workflow' and 'Add Github Actions Security workflow'. The workflow triggers on workflow_dispatch and on any unfiltered push (any branch or tag). GITHUB_TOKEN is scoped to contents: read, so the value lies in the repository's configured Actions secrets, not in the token.

GitGuardian reports that between 2026-08-31 and 2026-09-30 the August-September wave (workflow github_actions_security.yml) hit 772 public repositories across 373 users/organizations in three waves (Aug 31: 143 repos; Sept 2-5: 400 repos; Sept 15: 103 repos), targeting 2,577 secrets. The attacker appears to have scraped existing workflow and config history for ${{ secrets.NAME }} references and hard-coded those names into the payload. Targeted secret types by frequency included SSH/deployment keys (446), Azure (218), DockerHub/GHCR (142), database credentials (112), AWS keys (106), FTP (92), Google Cloud/Firebase (80), GitHub tokens (66), plus Telegram/Slack/Discord bot tokens, npm, PyPI and Cloudflare keys. Of 3,669 runs only 499 executed; the rest were held for approval. StepSecurity noted that one repository with mandatory workflow approval blocked exfiltration.

On 2026-10-08 the operator used two compromised maintainer accounts to push an upgraded 'Security Audit' (security-audit.yml) payload: kitao (Takashi Kitao, author of pyxel, about 18,400 stars) pushed to 27 repositories from 13:20 UTC, and henrywoo (Henry Wu) pushed to 318 repositories between 21:10 and 21:26 UTC, including the org-owned uber/athenadriver, to which the account retained write access. Socket counted 346 repositories in this burst, and 279 forks in the henrywoo namespace inherit the workflow. The upgraded variant (a) appends named Actions secrets, (b) greps the working directory for 13 credential patterns (AWS AKIA/ASIA keys and secret keys, Anthropic sk-ant-, OpenAI sk-proj-, OpenRouter sk-or-, GitHub classic and fine-grained PATs, GitLab, Google/Firebase, Slack, SendGrid), (c) mines full history with fetch-depth: 0 and 'git log -p --all | head -200000', and (d) captures +/-2 lines of context around AWS key matches delimited by AKIA_CTX_START / AKIA_CTX_END. Everything is sent in one cleartext HTTP POST to http://193.32.204.199/ with a 20-second timeout. Because history is swept, credentials committed and deleted years earlier are exposed, so rotating only current secrets is insufficient. As of 2026-10-09 StepSecurity counted 378 repositories hosting the live payload and 182 with history-mining markers. Socket identified 500+ accounts committing the malicious workflow. No malicious package releases from stolen credentials had been observed at publication time.

Exfiltration infrastructure has rotated: a Plesk-hosted domain (Sept 2025), 170.39.218.2 (Oct 2025-Apr 2026), Interactsh *.oast.fun endpoints (about 250 repos, Nov 2025 and Mar-Apr 2026), then raw IP 193.32.204.199 (from about 2026-09-04) including a port-3000 injection-tracking variant. Separately, a cryptominer (XMRig 6.21.0, pool.supportxmr.com:3333) was embedded in a kuafuai/DevOpsGPT Docker image on 2026-08-30; GitGuardian assesses this as likely a separate actor exploiting the same compromised account rather than the GhostAction operator. Attribution of GhostAction is unknown. The motivation is assessed as financial/credential theft for follow-on access, which is an analyst inference, not a sourced statement.

MITRE ATT&CK techniques used in TL-2026-3157

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1550.001 Use Alternate Authentication Material: Application Access Token

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol

Execution

T1059.004 Unix Shell; T1677 Poisoned Pipeline Execution

Command and Control

T1071.001 Web Protocols

Initial Access

T1078 Valid Accounts; T1195.002 Compromise Software Supply Chain

Collection

T1213.003 Code Repositories

Impact

T1496.001 Compute Hijacking

Credential Access

T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.004 Unsecured Credentials: Private Keys

Affected products and versions in GhostAction: Credential-Stealing GitHub Actions Workflows

  • GitHub — GitHub Actions workflows in repositories of compromised maintainer accounts
    Vulnerable versions: Repositories with workflows added since 2026-08-31 by compromised accounts
  • kitao — pyxel and 26 other repositories
    Vulnerable versions: Default branches pushed 2026-10-08
  • Uber — athenadriver
    Vulnerable versions: Default branch pushed 2026-10-08

Remediation for GhostAction: Credential-Stealing GitHub Actions Workflows

Immediate actions

  • Audit all repositories (and forks, private forks, downstream mirrors) for security-audit.yml, github_actions_security.yml and security-check.yml created since 2026-08-31; treat any hit as a confirmed breach
  • Revoke (not just rotate) the GitHub credentials, PATs, sessions and SSH keys of the maintainer account that allowed the injection
  • Rotate every exposed Actions secret and every credential ever committed to any branch or tag, since the October variant mines full git history
  • Delete the malicious workflow from all branches and revert the injecting commits
  • Block egress to 193.32.204.199 (ports 80 and 3000) and review runner logs for POSTs to it
  • Review package registry (PyPI, npm, DockerHub, GHCR) release history during the exposure window and defer releases until publishing secrets are rotated

Workarounds

  • Restrict Actions to an allow-list and require approval for all workflow runs until audit is complete

Longer-term hardening

  • Require pull-request review via branch protection / CODEOWNERS on .github/workflows/*
  • Enable mandatory approval for workflow runs; one repository with this control blocked exfiltration
  • Apply runner egress allow-lists (e.g. Harden-Runner allowed-endpoints) so raw-IP destinations are blocked
  • Enable GitHub secret scanning with push protection and enforce phishing-resistant MFA for maintainers
  • Remove stale write access for former contributors to organization repositories

Weaknesses (CWE) in GhostAction: Credential-Stealing GitHub Actions Workflows

CWE-522, CWE-798, CWE-506

Timeline of GhostAction: Credential-Stealing GitHub Actions Workflows

  • First GhostAction wave: malicious github_actions_security.yml workflows committed ('Add Github Actions Security workflow'); GitGuardian notices the FastUUID maintainer account was compromised.
  • First GhostAction campaign documented by GitGuardian: about 817 repositories, 327 users and 3,325 secrets exfiltrated, initially to a Plesk-hosted domain (bold-dhawan.45-139-104-115.plesk.page).
  • Second wave of the 2025 campaign observed, with about 500 new commits carrying a similar malicious workflow payload.
  • From October 2025 through April 2026 exfiltration shifted to 170.39.218.2, with *.oast.fun (Interactsh) endpoints used on about 250 repos in Nov 2025 and Mar-Apr 2026.
  • XMRig 6.21.0 miner (pool.supportxmr.com:3333) embedded in the kuafuai/DevOpsGPT Docker image; assessed as likely a separate actor abusing the same compromised account.
  • August-September wave begins: github_actions_security.yml injected into 143 repositories on the first day.
  • Raw-IP endpoint 193.32.204.199 observed live per StepSecurity.
  • Sept 2-5 wave reaches about 400 repositories; account xxyangyoulin infected on Sept 5.
  • Variant workflow security-check.yml with commit 'Add security check workflow' appears from 2026-09-07 onwards.
  • Third wave adds 103 repositories; by 2026-09-30 totals reach 772 public repos across 373 users/orgs and 2,577 secrets targeted.
  • GitGuardian collected 3,669 runs across 605 repositories: 499 executed in 32 repositories and 336 completed successfully, exfiltrating 26 secrets from 13 repositories.
  • Only about 16% (124) of the 772 affected repositories from the Aug-Sept 2026 wave had the malicious workflow effectively removed from public commit history.
  • GitGuardian publishes 'The campaign that never stopped: tracking GhostAction from 2025 to 2026'.
  • Compromised henrywoo account pushes the workflow to 318 repositories incl. uber/athenadriver between 21:10 and 21:26 UTC; exfiltration confirmed with C2 reply 'OK' at 21:26:04Z.
  • Compromised kitao account pushes security-audit.yml to 27 repositories including kitao/pyxel from 13:20 UTC.
  • StepSecurity, Socket and The Hacker News publish; 378 repositories host the live payload and 500+ accounts identified committing malicious workflows.

Update history for TL-2026-3157

Sources cited for GhostAction: Credential-Stealing GitHub Actions Workflows

Detection coverage for TL-2026-3157

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3157 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
38 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats