Threat reportSupply ChainTL-2026-3157
GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories
GhostAction: Credential-Stealing GitHub Actions Workflows (TL-2026-3157), also tracked as GhostAction, is a high-severity supply-chain compromise, first published 2026-10-09 and last reviewed 2026-10-10. It has no confirmed attribution, affects GitHub GitHub Actions workflows in repositories of compromised, maps to 15 MITRE ATT&CK techniques (T1027.002, T1036.005, T1041), and is covered by 9 detection rules and 38 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 38Indicators of compromise
Key facts for TL-2026-3157
- Threat ID
- TL-2026-3157
- Also known as
- GhostAction, GhostAction Returns
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, open-source
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 38
- Updates
- 2026-10-10 · 3 updates · revalidated 3× · latest source
Malware and tooling in GhostAction: Credential-Stealing GitHub Actions Workflows
Malware and tooling: xmrig
How GhostAction: Credential-Stealing GitHub Actions Workflows works
Malicious GitHub Actions workflows disguised as security audits (security-audit.yml, github_actions_security.yml) were committed to default branches through compromised maintainer GitHub accounts. They exfiltrate CI/CD secrets, and in the October 2026 variant also committed credentials from the working tree and full git history, over plain HTTP to the hard-coded IP 193.32.204.199.
GhostAction is a GitHub Actions supply-chain credential-theft campaign first documented in September 2025 (GitGuardian: about 817 repositories, 327 users, 3,325 secrets exfiltrated) and resurfacing from 2026-08-31. The operator obtains a maintainer's GitHub credential through a means not established in the sources, then commits a workflow that looks like a security audit directly to the default branch, bypassing pull-request review. Commit messages seen include 'Add security audit workflow', 'Update security audit workflow' and 'Add Github Actions Security workflow'. The workflow triggers on workflow_dispatch and on any unfiltered push (any branch or tag). GITHUB_TOKEN is scoped to contents: read, so the value lies in the repository's configured Actions secrets, not in the token.
GitGuardian reports that between 2026-08-31 and 2026-09-30 the August-September wave (workflow github_actions_security.yml) hit 772 public repositories across 373 users/organizations in three waves (Aug 31: 143 repos; Sept 2-5: 400 repos; Sept 15: 103 repos), targeting 2,577 secrets. The attacker appears to have scraped existing workflow and config history for ${{ secrets.NAME }} references and hard-coded those names into the payload. Targeted secret types by frequency included SSH/deployment keys (446), Azure (218), DockerHub/GHCR (142), database credentials (112), AWS keys (106), FTP (92), Google Cloud/Firebase (80), GitHub tokens (66), plus Telegram/Slack/Discord bot tokens, npm, PyPI and Cloudflare keys. Of 3,669 runs only 499 executed; the rest were held for approval. StepSecurity noted that one repository with mandatory workflow approval blocked exfiltration.
On 2026-10-08 the operator used two compromised maintainer accounts to push an upgraded 'Security Audit' (security-audit.yml) payload: kitao (Takashi Kitao, author of pyxel, about 18,400 stars) pushed to 27 repositories from 13:20 UTC, and henrywoo (Henry Wu) pushed to 318 repositories between 21:10 and 21:26 UTC, including the org-owned uber/athenadriver, to which the account retained write access. Socket counted 346 repositories in this burst, and 279 forks in the henrywoo namespace inherit the workflow. The upgraded variant (a) appends named Actions secrets, (b) greps the working directory for 13 credential patterns (AWS AKIA/ASIA keys and secret keys, Anthropic sk-ant-, OpenAI sk-proj-, OpenRouter sk-or-, GitHub classic and fine-grained PATs, GitLab, Google/Firebase, Slack, SendGrid), (c) mines full history with fetch-depth: 0 and 'git log -p --all | head -200000', and (d) captures +/-2 lines of context around AWS key matches delimited by AKIA_CTX_START / AKIA_CTX_END. Everything is sent in one cleartext HTTP POST to http://193.32.204.199/ with a 20-second timeout. Because history is swept, credentials committed and deleted years earlier are exposed, so rotating only current secrets is insufficient. As of 2026-10-09 StepSecurity counted 378 repositories hosting the live payload and 182 with history-mining markers. Socket identified 500+ accounts committing the malicious workflow. No malicious package releases from stolen credentials had been observed at publication time.
Exfiltration infrastructure has rotated: a Plesk-hosted domain (Sept 2025), 170.39.218.2 (Oct 2025-Apr 2026), Interactsh *.oast.fun endpoints (about 250 repos, Nov 2025 and Mar-Apr 2026), then raw IP 193.32.204.199 (from about 2026-09-04) including a port-3000 injection-tracking variant. Separately, a cryptominer (XMRig 6.21.0, pool.supportxmr.com:3333) was embedded in a kuafuai/DevOpsGPT Docker image on 2026-08-30; GitGuardian assesses this as likely a separate actor exploiting the same compromised account rather than the GhostAction operator. Attribution of GhostAction is unknown. The motivation is assessed as financial/credential theft for follow-on access, which is an analyst inference, not a sourced statement.
MITRE ATT&CK techniques used in TL-2026-3157
Defense Evasion
T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1550.001 Use Alternate Authentication Material: Application Access Token
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Execution
T1059.004 Unix Shell; T1677 Poisoned Pipeline Execution
Command and Control
Initial Access
T1078 Valid Accounts; T1195.002 Compromise Software Supply Chain
Collection
Impact
Credential Access
T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.004 Unsecured Credentials: Private Keys
Affected products and versions in GhostAction: Credential-Stealing GitHub Actions Workflows
- GitHub — GitHub Actions workflows in repositories of compromised maintainer accounts
Vulnerable versions: Repositories with workflows added since 2026-08-31 by compromised accounts - kitao — pyxel and 26 other repositories
Vulnerable versions: Default branches pushed 2026-10-08 - Uber — athenadriver
Vulnerable versions: Default branch pushed 2026-10-08
Remediation for GhostAction: Credential-Stealing GitHub Actions Workflows
Immediate actions
- Audit all repositories (and forks, private forks, downstream mirrors) for security-audit.yml, github_actions_security.yml and security-check.yml created since 2026-08-31; treat any hit as a confirmed breach
- Revoke (not just rotate) the GitHub credentials, PATs, sessions and SSH keys of the maintainer account that allowed the injection
- Rotate every exposed Actions secret and every credential ever committed to any branch or tag, since the October variant mines full git history
- Delete the malicious workflow from all branches and revert the injecting commits
- Block egress to 193.32.204.199 (ports 80 and 3000) and review runner logs for POSTs to it
- Review package registry (PyPI, npm, DockerHub, GHCR) release history during the exposure window and defer releases until publishing secrets are rotated
Workarounds
- Restrict Actions to an allow-list and require approval for all workflow runs until audit is complete
Longer-term hardening
- Require pull-request review via branch protection / CODEOWNERS on .github/workflows/*
- Enable mandatory approval for workflow runs; one repository with this control blocked exfiltration
- Apply runner egress allow-lists (e.g. Harden-Runner allowed-endpoints) so raw-IP destinations are blocked
- Enable GitHub secret scanning with push protection and enforce phishing-resistant MFA for maintainers
- Remove stale write access for former contributors to organization repositories
Weaknesses (CWE) in GhostAction: Credential-Stealing GitHub Actions Workflows
Timeline of GhostAction: Credential-Stealing GitHub Actions Workflows
- First GhostAction wave: malicious github_actions_security.yml workflows committed ('Add Github Actions Security workflow'); GitGuardian notices the FastUUID maintainer account was compromised.
- First GhostAction campaign documented by GitGuardian: about 817 repositories, 327 users and 3,325 secrets exfiltrated, initially to a Plesk-hosted domain (bold-dhawan.45-139-104-115.plesk.page).
- Second wave of the 2025 campaign observed, with about 500 new commits carrying a similar malicious workflow payload.
- From October 2025 through April 2026 exfiltration shifted to 170.39.218.2, with *.oast.fun (Interactsh) endpoints used on about 250 repos in Nov 2025 and Mar-Apr 2026.
- XMRig 6.21.0 miner (pool.supportxmr.com:3333) embedded in the kuafuai/DevOpsGPT Docker image; assessed as likely a separate actor abusing the same compromised account.
- August-September wave begins: github_actions_security.yml injected into 143 repositories on the first day.
- Raw-IP endpoint 193.32.204.199 observed live per StepSecurity.
- Sept 2-5 wave reaches about 400 repositories; account xxyangyoulin infected on Sept 5.
- Variant workflow security-check.yml with commit 'Add security check workflow' appears from 2026-09-07 onwards.
- Third wave adds 103 repositories; by 2026-09-30 totals reach 772 public repos across 373 users/orgs and 2,577 secrets targeted.
- GitGuardian collected 3,669 runs across 605 repositories: 499 executed in 32 repositories and 336 completed successfully, exfiltrating 26 secrets from 13 repositories.
- Only about 16% (124) of the 772 affected repositories from the Aug-Sept 2026 wave had the malicious workflow effectively removed from public commit history.
- GitGuardian publishes 'The campaign that never stopped: tracking GhostAction from 2025 to 2026'.
- Compromised henrywoo account pushes the workflow to 318 repositories incl. uber/athenadriver between 21:10 and 21:26 UTC; exfiltration confirmed with C2 reply 'OK' at 21:26:04Z.
- Compromised kitao account pushes security-audit.yml to 27 repositories including kitao/pyxel from 13:20 UTC.
- StepSecurity, Socket and The Hacker News publish; 378 repositories host the live payload and 500+ accounts identified committing malicious workflows.
Update history for TL-2026-3157
- 2026-10-10 — GhostAction: Persistent GitHub Actions Supply Chain Campaign Resurges with Malicious Workflows Exfiltrating CI/CD Secrets (2025-2026): What changed No severity, exploitability, status or attribution change; the existing HIGH / ACTIVE / Unattributed values stand. The update adds detail only. New indicators (10) 10 new indicators, mostly artifacts from the DevOpsGPT XMRig in
- 2026-10-10 — GhostAction Supply Chain Campaign Uses Malicious GitHub Actions Workflows to Steal CI/CD Credentials: What changed No severity, exploitability or status change (HIGH / ACTIVE stay as is). Additive context only. New indicators (3) 3 new indicators: the injected workflow path, the 'curl -s -X POST' exfil command and the 493networking.cc hosti
- 2026-10-09 — GhostAction: Hijacked GitHub Maintainer Accounts Inject Malicious 'Security Audit' Workflows into 346 Repos to Steal CI/CD Secrets: What changed No field escalation; severity HIGH, exploitability ACTIVE and status ACTIVE already match the report. New indicators (7) 2 first-wave C2 domains (objective-hopper.45-139-104-115.plesk.page, carte-avantage.com), 3 commit-message
Sources cited for GhostAction: Credential-Stealing GitHub Actions Workflows
- Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories (The Hacker News)
- GhostAction Returns: Malicious 'Security Audit' Workflows Now Mine Credentials from Entire Git Histories (StepSecurity)
- New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials (Socket)
- GhostAction Returns: 772 Repos Hit in New GitHub Actions Wave (GitGuardian)
- The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows (GitGuardian, 2025 campaign)
- New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets (Cyber Security News)
Detection coverage for TL-2026-3157
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3157 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.