www.stepsecurity.io 9 Oct 2026, 14:42 UTC

GhostAction Campaign Hijacks Maintainers to Steal Secrets From 345 Repositories

CyberSIXT Evidence Panel Source marked as original reporting

ON 9 October 2026, StepSecurity reports a renewed GhostAction campaign that compromised two high-profile GitHub maintainers and swept hundreds of repositories in rapid succession. Using the compromised accounts of Takashi Kitao (pyxel) and Henry Wu (athenadriver), attackers pushed a malicious workflow to 27 repositories and then to 318 more within minutes, transferring control via the victim’s own identities.

The exfiltration targeted the repository’s named GitHub Actions secrets and, crucially, every credential found in the working tree and the entire Git history, transmitted to a hardcoded IP address over plain HTTP. Initial evidence from Uber’s athenadriver repository confirms the exfiltration completed within seconds of the workflow running, underscoring the attackers’ use of trusted maintainer credentials.

The attackers’ payload, now branded as “Security Audit” (security-audit[.]yml), expands beyond earlier waves by harvesting the full git history. Variant B iterates four steps: (1) append named secrets to exfil payload when present, (2) sweep the working tree for more credential patterns, (3) search the entire git history via git log -p --all, and (4) pair AWS key IDs with their corresponding secrets by capturing surrounding context.

Exfiltration is staged through a bare IP endpoint (193.32.204[.]199) and markers such as AKIA_CTX_START/END and ?c=monami or ?c=new to differentiate recovery status. At time of writing, around 378 repositories show a live malicious workflow on default branches, with 182 containing the history-mining marker and 88 bearing the named-secrets marker.

Immediate remediation remains: rotate all credentials ever committed, revoke the compromised GitHub credential, delete the malicious workflow across all branches, and audit runs since 31 August 2026.

View full article

Article by CyberSIXT