Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
GhostAction Credential Stealer Returns: Hijacked Maintainer Accounts Push Malicious Workflow to 340-Plus GitHub Repos

A supply chain campaign called GhostAction is back, and the latest burst is doing more damage than the one before it.
On Oct. 8, two hijacked maintainer accounts pushed a malicious GitHub Actions workflow into 346 repositories in two automated sweeps lasting minutes, according to Socket's analysis, which GitGuardian cited in an update posted today, Oct. 9. StepSecurity's timeline breaks it down. The account of Takashi Kitao, author of the game engine pyxel (roughly 18,400 stars), was used to push the file to 27 repositories starting at 13:20 UTC. Eight hours later, the account of Henry Wu (henrywoo), original author of Uber's athenadriver, was used to hit 318 repositories in a 16-minute window, 21:10 to 21:26 UTC.
What the workflow does
The file is named either security-audit.yml or github_actions_security.yml. It poses as a security check.
It is not one. StepSecurity says it triggers on a manual dispatch and on any push to any branch or tag, checks out the repository's full history, and runs a single "Audit" step. The step ships stolen data over plain, unencrypted HTTP to a hard-coded IP address, 193.32.204.199.
This variant goes further than past waves. Socket reports it sweeps the working tree and the entire git history for cloud credentials, not just the GitHub Actions secrets a repository names. The targets include AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens.
Socket also reports that, unlike the earlier wave, these runs executed and exfiltration succeeded. Socket said that as of today it has identified more than 500 GitHub accounts that committed the workflow to tens of thousands of repositories since Oct. 7. That figure is far larger than the 346 repositories tied to the two maintainer accounts, and GitGuardian said it is still reviewing the new wave against its own data.
The September wave
GitGuardian researchers Gaetan Ferry and Guillaume Valadon published their findings on the earlier surge on Oct. 7. Between Aug. 31 and Sept. 30, 2026, the campaign hit 772 public repositories belonging to 373 GitHub users and organizations. Cynative independently spotted the malicious commits and alerted GitGuardian.
The workflows targeted 2,577 secrets. SSH keys and deployment credentials made up 446 of them, followed by 218 Azure credentials, 142 container registry credentials, 112 database credentials and 106 AWS access keys.
GitGuardian stressed that targeted does not mean stolen. Of 3,669 workflow runs across 605 repositories, GitHub's approval mechanism held most of them. Only 499 runs executed, in 32 repositories, and 336 completed. Researchers confirmed 26 secrets exfiltrated from 13 repositories. GitGuardian also noted that some collected values, such as hostnames and usernames, are not sensitive on their own, though they can help in follow-on attacks.
The researchers describe this as abuse of stolen repository access, not a flaw in GitHub Actions. Commits appeared under the victims' own identities. GitGuardian said the attacker likely used previously compromised credentials.
That is the strongest counterpoint to alarm over the September numbers, and it is the researchers' own. GitHub's approval gate worked. The October runs reportedly did not stall the same way.
A persistent operation
GhostAction was first documented in September 2025. That wave hit 817 repositories across 327 users and exfiltrated 3,325 secrets, including PyPI, npm and DockerHub tokens. The technique was later reused in the Shai-Hulud campaigns and remains part of the Mini Shai-Hulud malware family's credential collection, according to GitGuardian.
The attacker also adapts. The 2025 wave sent data to bold-dhawan.45-139-104-115.plesk.page and carte-avantage.com. The 2026 wave moved to a bare IP. On Sept. 7, a variant appeared in seven repositories under the name security-check.yml, posting to a dedicated API with a unique ID per injection. GitGuardian says that suggests the attacker tracks individual compromises on the back end.
In 92 recent cases, the attacker edited existing malicious workflows instead of adding new files, pointing older payloads at new infrastructure.
The attacker also appears to scrape each victim's workflow and config history for secret names, then requests exactly those values. That makes the output tidy and the file look routine.
StepSecurity and GitGuardian have also noted a cryptominer. On Aug. 30, the attackers altered the kuafuai/DevOpsGPT repository to embed an XMRig miner in the project's Docker image. As of StepSecurity's writing, no malicious package releases had been published using compromised publishing credentials.
Cleanup is the weak point
The September victims have mostly not fixed the problem. GitGuardian found only 124 repositories, about 16% of those affected, showed effective remediation in public history by Oct. 5.
The malicious workflows trigger on every push, so ordinary, legitimate commits after an injection set off most of the observed runs.
Researchers advise developers to check repositories for either workflow file going back to Aug. 31 and to assume compromise if one is found. Rotating the stolen secrets is not enough on its own. The GitHub credentials that allowed the injection also have to be revoked, and git history needs review, since the new variant reads it.
Open questions
No one has said who is behind the campaign or how the attacker obtained the maintainers' credentials. Socket's count of more than 500 accounts and tens of thousands of repositories has not been reconciled with the 346 repositories tied to the two maintainer accounts. GitGuardian's review of the October wave against its own data is still under way.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.