Essential Insights
- Attackers exploited high-profile GitHub maintainer accounts to inject malicious workflows that exfiltrate sensitive secrets, including cloud API keys and tokens, from over 500 repositories since October 7, 2026.
- The campaign, linked to GhostAction, primarily uses stolen credentials to inject malicious workflows that scan repositories for secrets, exfiltrate data via plain HTTP, and potentially embed cryptominers or other payloads.
- Downstream forks and private repositories are especially vulnerable, with compromised workflows persisting across forks and inheriting malicious behavior, risking further credential leaks and unauthorized access.
Threat, Techniques, and Targets
Cybersecurity experts have identified an ongoing campaign involving credential theft. This campaign is linked to a group called GhostAction. The attackers took control of two important GitHub accounts. They used these accounts to push malicious workflows to many repositories. In total, the activity affected over 340 repositories initially, and more than 500 GitHub accounts have now been involved. The attackers targeted open-source projects, especially those with many followers or active contributions. Their goal was to steal sensitive data such as secrets, API keys, and credentials for cloud services like AWS, Azure, and Google Cloud. They also aimed to steal tokens from platforms like GitHub and GitLab. The threat actors used techniques like obtaining stolen credentials, scanning for secrets, injecting malicious workflows, and exfiltrating data over plain HTTP. The malicious workflows imitate legitimate security scans but secretly steal data instead.
Impact, Security Implications, and Guidance
This campaign results in significant risks for affected developers and organizations. The stolen secrets include access keys, API tokens, and private keys. These can be used by hackers to control cloud resources, access private data, or launch further attacks. The impact poses a serious security concern, especially for open-source projects and downstream users. Developers should act quickly to check their repositories for the malicious workflows. They should revoke compromised credentials and delete the malicious files. It is also important to rotate secrets and examine forks for signs of infection. Downstream projects and forks are particularly vulnerable if they inherit compromised workflows. For most effective remediation, users should seek guidance from their platform provider or security authority.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
