GhostAction Supply Chain Campaign Resurfaces, Targeting GitHub Secrets
A renewed wave of the GhostAction supply chain attack has compromised 772 public GitHub repositories across 373 users and organizations, exposing 2,577 secrets in CI/CD pipelines. Tracked by GitGuardian between August 31 and September 30, 2026, the campaign was first identified by Cynative researchers after detecting malicious commits.
Attackers inserted GitHub Actions workflows disguised as security checks primarily a file named github_actions_security.yml to exfiltrate deployment keys, cloud credentials, and API tokens to an attacker-controlled server (193.32.204.199) via unencrypted HTTP. A secondary variant, security-check.yml, appeared in seven repositories on September 7, sending data to a different endpoint with a unique injection ID, suggesting backend tracking.
The campaign targeted a range of sensitive credentials, including:
- 446 SSH/deployment keys
- 218 Azure entries
- 142 container registry tokens
- 112 database credentials
- 106 AWS access keys
- GitHub, Google Cloud, Firebase, and package registry credentials
Despite 3,669 observed workflow runs across 605 repositories, only 499 executed in 32 repositories, with 336 successful runs exfiltrating 26 secrets from 13 repositories. Most runs were held for approval by GitHub.
Cleanup efforts remained minimal: By October 5, only 16% (124 repositories) had removed the malicious workflows. In 92 cases, attackers updated existing payloads rather than planting new ones, redirecting exfiltration to the latest server.
Researchers also uncovered an XMRig cryptominer hidden in the kuafuai/DevOpsGPT repository, embedded in a Docker image with XOR-encrypted configuration and a fake health check to maintain persistence. While the same compromised account later injected GhostAction workflows, no direct link between the miner and the supply chain attack was established. Overlaps with four distinct mining campaigns in 13 victim repositories suggested separate operators.
GhostAction was first disclosed in September 2025, when it affected 817 repositories and stole 3,325 secrets, indicating the campaign has persisted between major waves.
Source: https://cyberpress.org/ghostaction-targets-github-secrets/
GitHub cybersecurity rating report: https://www.rankiteo.com/company/github
"id": "GIT1791448157",
"linkid": "github",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology, Software Development, Cloud '
'Services',
'location': 'Global',
'name': '373 GitHub users and organizations',
'size': 'Varies (small to large enterprises)',
'type': 'Individuals and organizations'},
{'industry': 'Software Development',
'name': 'kuafuai/DevOpsGPT (repository)',
'type': 'Repository'}],
'attack_vector': 'Malicious GitHub Actions workflows '
'(github_actions_security.yml, security-check.yml)',
'data_breach': {'data_encryption': 'No (exfiltrated via unencrypted HTTP); '
'XOR-encrypted XMRig miner configuration',
'data_exfiltration': 'Yes (to attacker-controlled server '
'193.32.204.199 via unencrypted HTTP)',
'number_of_records_exposed': '2,577 secrets',
'personally_identifiable_information': 'Potential '
'(credentials, access '
'tokens)',
'sensitivity_of_data': 'High (credentials, API tokens, '
'deployment keys)',
'type_of_data_compromised': ['SSH/deployment keys',
'Azure credentials',
'Container registry tokens',
'Database credentials',
'AWS access keys',
'GitHub tokens',
'Google Cloud credentials',
'Firebase credentials',
'Package registry credentials']},
'date_detected': '2026-08-31',
'date_publicly_disclosed': '2026-09-30',
'description': 'A renewed wave of the GhostAction supply chain attack has '
'compromised 772 public GitHub repositories across 373 users '
'and organizations, exposing 2,577 secrets in CI/CD pipelines. '
'Attackers inserted GitHub Actions workflows disguised as '
'security checks to exfiltrate deployment keys, cloud '
'credentials, and API tokens to an attacker-controlled server '
'via unencrypted HTTP.',
'impact': {'brand_reputation_impact': 'Potential reputational damage to '
'affected organizations',
'data_compromised': '2,577 secrets (SSH keys, cloud credentials, '
'API tokens, database credentials)',
'identity_theft_risk': 'High (exposure of PII, credentials, and '
'access tokens)',
'operational_impact': 'Minimal cleanup (16% of repositories '
'remediated by October 5, 2026)',
'systems_affected': '772 public GitHub repositories, CI/CD '
'pipelines'},
'initial_access_broker': {'entry_point': 'Malicious GitHub Actions workflows '
'(github_actions_security.yml, '
'security-check.yml)',
'high_value_targets': 'CI/CD pipelines, cloud '
'credentials, deployment '
'keys'},
'investigation_status': 'Ongoing (as of October 5, 2026)',
'lessons_learned': 'Supply chain attacks via CI/CD pipelines remain '
'persistent; minimal cleanup efforts by affected entities; '
'attackers adapt payloads to evade detection.',
'motivation': 'Data exfiltration (credentials, tokens), potential '
'cryptomining (XMRig)',
'post_incident_analysis': {'corrective_actions': ['Rotate all exposed '
'credentials',
'Remove malicious workflows '
'from repositories',
'Implement stricter CI/CD '
'pipeline security',
'Monitor for unauthorized '
'access and exfiltration'],
'root_causes': ['Exposed secrets in public GitHub '
'repositories',
'Lack of encryption for data '
'exfiltration',
'Minimal cleanup efforts by '
'affected entities',
'Persistent attacker adaptation '
'(payload updates)']},
'recommendations': ['Audit and secure GitHub Actions workflows',
'Rotate exposed credentials and tokens immediately',
'Monitor for unauthorized exfiltration attempts',
'Implement encrypted communication for sensitive data',
'Enhance repository access controls and approval '
'workflows'],
'references': [{'date_accessed': '2026-09-30', 'source': 'GitGuardian'},
{'source': 'Cynative researchers'}],
'response': {'containment_measures': 'Removal of malicious workflows (124 '
'repositories by October 5, 2026)',
'remediation_measures': 'Cleanup of malicious GitHub Actions '
'workflows',
'third_party_assistance': 'GitGuardian, Cynative researchers'},
'threat_actor': 'GhostAction campaign operators',
'title': 'GhostAction Supply Chain Campaign Resurfaces, Targeting GitHub '
'Secrets',
'type': 'Supply Chain Attack',
'vulnerability_exploited': 'Exposed secrets in CI/CD pipelines, unencrypted '
'HTTP exfiltration'}