SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
GhostAction uses hijacked maintainer accounts to plant a secret-stealing 'Security Audit' workflow
GhostAction's credential-stealing GitHub workflow has reached tens of thousands of repositories through more than 500 accounts since October 7, Socket says. Any repository carrying the file should be treated as having lost its Actions secrets and every key in its git history.
The Watch · Security desk

What happened
- StepSecurity traced pushes to two hijacked accounts: pyxel author Takashi Kitao's reached 27 repositories, and eight hours later Henry Wu's reached 318 in 16 minutes.
- The file is named security-audit.yml or github_actions_security.yml and sends stolen data over plain HTTP to the hard-coded address 193.32.204[.]199.
- GhostAction first surfaced in September 2025, when it hit 817 repositories across 327 GitHub users and exfiltrated 3,325 secrets, including PyPI, npm and DockerHub tokens.
- As of the report, no malicious package release had been published using stolen publishing credentials.
- Anyone who finds either file in commits since August 31, 2026 is advised to assume compromise, revoke the GitHub credential, rotate secrets, purge every branch and check forks.
Why it matters
- cost Rotation has to cover every credential ever committed to an affected repository, including ones deleted long ago, on top of the current Actions secrets.
- exposure Fork and mirror owners who never lost an account can still run the harvester by syncing from an infected upstream with Actions enabled.
- decision Teams that revoke PyPI, npm and DockerHub tokens now cut off the route to their downstream users while no release has yet been pushed with them.
- precedent A campaign first seen in 2025 is running again on maintainer tokens likely taken from infostealer logs, so a token that leaked once stays an entry point until it is revoked.
Henry Wu's account pushed the workflow at about 20 repositories a minute [18]. That pace fits a script working from a stolen token. According to The Hacker News's account of the chain, the attacker most likely starts with a maintainer's personal access token leaked through infostealer logs or credential dumps [6]. The repository's workflow files are scanned first to learn which secrets it holds. The fake audit workflow then lands on the default branch under the victim's own identity, and curl sends the results to an attacker-controlled endpoint [7].
"It triggers on workflow_dispatch and an unfiltered push (any branch, any tag), checks out with fetch-depth: 0, and runs a single 'Audit' step that does four things," StepSecurity said [8]. The step appends the named secrets found during reconnaissance, matches 13 credential patterns against the working tree, runs the same patterns across the whole git history, and pairs AWS access key IDs with their secret keys [9]. The full-depth checkout is how it reaches a key that was committed once and deleted later [9]. Stolen material includes AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens [5]. GitGuardian put the target list at 2,577 secrets, among them SSH private keys, DockerHub and GHCR registry credentials, and npm and PyPI keys [11].
The tens-of-thousands count is Socket's alone [2]. The two accounts StepSecurity traced pushed to 345 repositories [17]. GitGuardian counted 772 public repositories belonging to 373 users and organizations between August 31 and September 30, 2026 [10]. The earliest dated activity in the report is August 30, 2026, when the attackers altered the kuafuai/DevOpsGPT repository to embed an XMRig cryptocurrency miner in its Docker image [12]. The report does not say how the other accounts in Socket's count were taken over. Taking 10,000 as the floor for "tens of thousands", Socket's figure is at least 12 times the first wave's repository count [19].
Every branch has to be cleaned. The workflow fires on a push to any branch or tag [8], so a copy left on a stale branch runs the next time someone pushes there. Forks hold their own copies. "The 279 forks in the henrywoo namespace each carry the workflow file. If Actions are enabled, subsequent pushes can trigger credential harvesting," Socket said [15]. "Downstream forks are also at risk if they inherit the malicious workflow, either when newly created or by synchronizing with the affected upstream repository," Socket added [16].
What to watch
- A PyPI, npm or DockerHub release published with credentials stolen in this wave would move the campaign from collecting secrets to poisoning packages.
- Socket publishing its repository list or the takeover method behind its 500-plus accounts would let others test the tens-of-thousands figure.
- New workflow file names or an exfiltration address other than 193.32.204[.]199 would leave searches built on the current indicators blind.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC; eight hours later the account of Henry Wu (henrywoo), original author of Uber's athenadriver, pushed the same workflow to 318 repositories in a 16-minute window, 21:10-21:26 UTC.
- [2]
As of October 9, 2026, Socket identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.
- [3]
The activity is attributed to GhostAction, a supply chain campaign that first came to light in September 2025 and impacted 817 repositories across 327 GitHub users, exfiltrating 3,325 secrets including PyPI, npm and DockerHub tokens.
- [4]
As before, the accounts pushed a workflow named Security Audit (security-audit.yml) or GitHub Actions Security (github_actions_security.yml), designed to exfiltrate data to the hard-coded IP address 193.32.204[.]199 over plain HTTP.
- [5]
Captured data includes the repository's named GitHub Actions secrets and credentials in the working tree and full git history, such as AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens.
- [6]
The attacker obtains a maintainer's GitHub credentials, most likely a leaked personal access token from infostealer logs or credential dumps.
- [7]
Workflow files are scanned for secrets as reconnaissance, a workflow posing as a security audit is injected into the default branch under the victim's own identity, and the payload sends extracted data to an attacker-controlled endpoint via curl.
- [8]
It triggers on workflow_dispatch and an unfiltered push (any branch, any tag), checks out with fetch-depth: 0, and runs a single 'Audit' step that does four things
- [9]
The Audit step appends the named secrets found during reconnaissance, scans the working tree for 13 credential patterns, checks the entire git history for the same patterns to harvest credentials committed and later deleted, and pairs AWS access key IDs with matching secret access keys.
- [10]
GitGuardian reported the campaign pushed the malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026.
- [11]
The injected workflows target 2,577 secrets, including SSH private keys, Azure credentials, DockerHub and GHCR registry credentials, database and AWS credentials, GitHub tokens, and Cloudflare, npm, PyPI and AI provider keys.
- [12]
In at least one case, on August 30, 2026, the attackers altered the kuafuai/DevOpsGPT repository to embed an XMRig cryptocurrency miner in the project's Docker image.
- [13]
As of writing, no malicious package releases have been published using compromised publishing credentials.
- [14]
Developers are advised to check repositories for either workflow since August 31, 2026, assume compromise if present, revoke the compromised GitHub credential, rotate credentials, delete the workflow from all branches, and check forks.
- [15]
The 279 forks in the henrywoo namespace each carry the workflow file. If Actions are enabled, subsequent pushes can trigger credential harvesting,
- [16]
Downstream forks are also at risk if they inherit the malicious workflow, either when newly created or by synchronizing with the affected upstream repository.
- [17]
The two accounts StepSecurity traced pushed the workflow to 345 repositories.
- [18]
Henry Wu's account pushed the workflow at about 20 repositories per minute.
- [19]
Taking 10,000 as a floor for 'tens of thousands', Socket's count is at least 12 times the 817 repositories hit in the 2025 wave.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comCredential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.