CYBERSECURITY researchers have disclosed a widespread GhostAction campaign that injects credential-stealing GitHub Actions workflows into thousands of repositories. The attackers breached the accounts of high-profile maintainers, including Takashi Kitao and Henry Wu, pushing malicious workflows to hundreds of repositories in short timeframes (beginning 13:20 UTC on 7 October 2026 for Kitao’s account and then from 21:10 to 21:26 UTC for Wu’s account).
By 9 October 2026, Socket and other researchers reported more than 500 GitHub accounts involved, with the malicious workflow appearing in tens of thousands of repositories. The forged workflows—typically named Security Audit (security-audit[.]yml) or GitHub Actions Security (github_actions_security.yml)—are designed to exfiltrate data to a fixed attacker-controlled endpoint via HTTP, using the workflow’s run to harvest a broad set of secrets from the repository and history.
The exfiltration payload collects repository-scoped secrets, including CI/CD credentials and cloud or SaaS keys present in the working tree and entire git history. Reports describe the attacker’s data collection as scanning for 13 credential patterns (covering AWS keys, AI service keys, SaaS tokens, and similar credentials) and then pairing AWS access keys with their secret keys.
The operation has exposed 2,577 secrets across impacted repos and users, with evidence suggesting downstream risk through forks and private repositories. Action after detection includes revoking compromised GitHub credentials, rotating secrets, removing the malicious workflow from all branches and forks, and reviewing downstream mirrors for inherited payloads. The campaign is attributed to GhostAction, a long-running supply-chain operation, and involves credential theft at scale across GitHub environments.