# GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories

> Malicious GitHub Actions workflows disguised as security audits (security-audit.yml, github_actions_security.yml) were committed to default branches through compromised maintainer GitHub accounts. They exfiltrate CI/CD secrets, and in the October 2026 variant also committed credentials from the working tree and full git history, over plain HTTP to the hard-coded IP 193.32.204.199.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-10T07:17:41.453Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3157
- **ID:** TL-2026-3157
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GhostAction is a GitHub Actions supply-chain credential-theft campaign first documented in September 2025 (GitGuardian: about 817 repositories, 327 users, 3,325 secrets exfiltrated) and resurfacing from 2026-08-31. The operator obtains a maintainer's GitHub credential through a means not established in the sources, then commits a workflow that looks like a security audit directly to the default branch, bypassing pull-request review. Commit messages seen include 'Add security audit workflow', 'Update security audit workflow' and 'Add Github Actions Security workflow'. The workflow triggers on workflow_dispatch and on any unfiltered push (any branch or tag). GITHUB_TOKEN is scoped to contents: read, so the value lies in the repository's configured Actions secrets, not in the token.

GitGuardian reports that between 2026-08-31 and 2026-09-30 the August-September wave (workflow github_actions_security.yml) hit 772 public repositories across 373 users/organizations in three waves (Aug 31: 143 repos; Sept 2-5: 400 repos; Sept 15: 103 repos), targeting 2,577 secrets. The attacker appears to have scraped existing workflow and config history for ${{ secrets.NAME }} references and hard-coded those names into the payload. Targeted secret types by frequency included SSH/deployment keys (446), Azure (218), DockerHub/GHCR (142), database credentials (112), AWS keys (106), FTP (92), Google Cloud/Firebase (80), GitHub tokens (66), plus Telegram/Slack/Discord bot tokens, npm, PyPI and Cloudflare keys. Of 3,669 runs only 499 executed; the rest were held for approval. StepSecurity noted that one repository with mandatory workflow approval blocked exfiltration.

On 2026-10-08 the operator used two compromised maintainer accounts to push an upgraded 'Security Audit' (security-audit.yml) payload: kitao (Takashi Kitao, author of pyxel, about 18,400 stars) pushed to 27 repositories from 13:20 UTC, and henrywoo (Henry Wu) pushed to 318 repositories between 21:10 and 21:26 UTC, including the org-owned uber/athenadriver, to which the account retained write access. Socket counted 346 repositories in this burst, and 279 forks in the henrywoo namespace inherit the workflow. The upgraded variant (a) appends named Actions secrets, (b) greps the working directory for 13 credential patterns (AWS AKIA/ASIA keys and secret keys, Anthropic sk-ant-, OpenAI sk-proj-, OpenRouter sk-or-, GitHub classic and fine-grained PATs, GitLab, Google/Firebase, Slack, SendGrid), (c) mines full history with fetch-depth: 0 and 'git log -p --all | head -200000', and (d) captures +/-2 lines of context around AWS key matches delimited by AKIA_CTX_START / AKIA_CTX_END. Everything is sent in one cleartext HTTP POST to http://193.32.204.199/ with a 20-second timeout. Because history is swept, credentials committed and deleted years earlier are exposed, so rotating only current secrets is insufficient. As of 2026-10-09 StepSecurity counted 378 repositories hosting the live payload and 182 with history-mining markers. Socket identified 500+ accounts committing the malicious workflow. No malicious package releases from stolen credentials had been observed at publication time.

Exfiltration infrastructure has rotated: a Plesk-hosted domain (Sept 2025), 170.39.218.2 (Oct 2025-Apr 2026), Interactsh *.oast.fun endpoints (about 250 repos, Nov 2025 and Mar-Apr 2026), then raw IP 193.32.204.199 (from about 2026-09-04) including a port-3000 injection-tracking variant. Separately, a cryptominer (XMRig 6.21.0, pool.supportxmr.com:3333) was embedded in a kuafuai/DevOpsGPT Docker image on 2026-08-30; GitGuardian assesses this as likely a separate actor exploiting the same compromised account rather than the GhostAction operator. Attribution of GhostAction is unknown. The motivation is assessed as financial/credential theft for follow-on access, which is an analyst inference, not a sourced statement.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1078 Valid Accounts
- T1677 Poisoned Pipeline Execution
- T1059.004 Unix Shell
- T1036.005 Match Legitimate Resource Name or Location
- T1552.001 Credentials In Files
- T1213.003 Code Repositories
- T1496.001 Compute Hijacking
- T1071.001 Web Protocols
- T1041 Exfiltration Over C2 Channel
- T1528 Steal Application Access Token
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1027.002 Obfuscated Files or Information: Software Packing
- T1552.004 Unsecured Credentials: Private Keys

## Sources

- [Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories (The Hacker News)](https://thehackernews.com/2026/10/credential-stealing-github-actions.html)
- [GhostAction Returns: Malicious 'Security Audit' Workflows Now Mine Credentials from Entire Git Histories (StepSecurity)](https://www.stepsecurity.io/blog/ghostaction-returns)
- [New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials (Socket)](https://socket.dev/blog/ghostaction-cloud-credentials)
- [GhostAction Returns: 772 Repos Hit in New GitHub Actions Wave (GitGuardian)](https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack-returns/)
- [The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows (GitGuardian, 2025 campaign)](https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/)
- [New GhostAction Attack Compromises Hundreds of GitHub Repos to Steal Secrets (Cyber Security News)](https://cybersecuritynews.com/ghostaction-github-repo-attack/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3157
