Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

GhostAction uses hijacked maintainer accounts to plant a secret-stealing 'Security Audit' workflow

GhostAction's credential-stealing GitHub workflow has reached tens of thousands of repositories through more than 500 accounts since October 7, Socket says. Any repository carrying the file should be treated as having lost its Actions secrets and every key in its git history.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying GhostAction uses hijacked maintainer accounts to plant a secret-stealing 'Security Audit' workflow
Generated illustration

What happened

  • StepSecurity traced pushes to two hijacked accounts: pyxel author Takashi Kitao's reached 27 repositories, and eight hours later Henry Wu's reached 318 in 16 minutes.
  • The file is named security-audit.yml or github_actions_security.yml and sends stolen data over plain HTTP to the hard-coded address 193.32.204[.]199.
  • GhostAction first surfaced in September 2025, when it hit 817 repositories across 327 GitHub users and exfiltrated 3,325 secrets, including PyPI, npm and DockerHub tokens.
  • As of the report, no malicious package release had been published using stolen publishing credentials.
  • Anyone who finds either file in commits since August 31, 2026 is advised to assume compromise, revoke the GitHub credential, rotate secrets, purge every branch and check forks.

Why it matters

  • cost Rotation has to cover every credential ever committed to an affected repository, including ones deleted long ago, on top of the current Actions secrets.
  • exposure Fork and mirror owners who never lost an account can still run the harvester by syncing from an infected upstream with Actions enabled.
  • decision Teams that revoke PyPI, npm and DockerHub tokens now cut off the route to their downstream users while no release has yet been pushed with them.
  • precedent A campaign first seen in 2025 is running again on maintainer tokens likely taken from infostealer logs, so a token that leaked once stays an entry point until it is revoked.

Henry Wu's account pushed the workflow at about 20 repositories a minute [18]. That pace fits a script working from a stolen token. According to The Hacker News's account of the chain, the attacker most likely starts with a maintainer's personal access token leaked through infostealer logs or credential dumps [6]. The repository's workflow files are scanned first to learn which secrets it holds. The fake audit workflow then lands on the default branch under the victim's own identity, and curl sends the results to an attacker-controlled endpoint [7].

"It triggers on workflow_dispatch and an unfiltered push (any branch, any tag), checks out with fetch-depth: 0, and runs a single 'Audit' step that does four things," StepSecurity said [8]. The step appends the named secrets found during reconnaissance, matches 13 credential patterns against the working tree, runs the same patterns across the whole git history, and pairs AWS access key IDs with their secret keys [9]. The full-depth checkout is how it reaches a key that was committed once and deleted later [9]. Stolen material includes AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens [5]. GitGuardian put the target list at 2,577 secrets, among them SSH private keys, DockerHub and GHCR registry credentials, and npm and PyPI keys [11].

The tens-of-thousands count is Socket's alone [2]. The two accounts StepSecurity traced pushed to 345 repositories [17]. GitGuardian counted 772 public repositories belonging to 373 users and organizations between August 31 and September 30, 2026 [10]. The earliest dated activity in the report is August 30, 2026, when the attackers altered the kuafuai/DevOpsGPT repository to embed an XMRig cryptocurrency miner in its Docker image [12]. The report does not say how the other accounts in Socket's count were taken over. Taking 10,000 as the floor for "tens of thousands", Socket's figure is at least 12 times the first wave's repository count [19].

Every branch has to be cleaned. The workflow fires on a push to any branch or tag [8], so a copy left on a stale branch runs the next time someone pushes there. Forks hold their own copies. "The 279 forks in the henrywoo namespace each carry the workflow file. If Actions are enabled, subsequent pushes can trigger credential harvesting," Socket said [15]. "Downstream forks are also at risk if they inherit the malicious workflow, either when newly created or by synchronizing with the affected upstream repository," Socket added [16].

What to watch

  • A PyPI, npm or DockerHub release published with credentials stolen in this wave would move the campaign from collecting secrets to poisoning packages.
  • Socket publishing its repository list or the takeover method behind its 500-plus accounts would let others test the tens-of-thousands figure.
  • New workflow file names or an exfiltration address other than 193.32.204[.]199 would leave searches built on the current indicators blind.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC; eight hours later the account of Henry Wu (henrywoo), original author of Uber's athenadriver, pushed the same workflow to 318 repositories in a 16-minute window, 21:10-21:26 UTC.

    ReportedSupportedSource: StepSecurity, via The Hacker NewsView cited source
  2. [2]

    As of October 9, 2026, Socket identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

    ReportedSupportedSource: Socket, via The Hacker NewsView cited source
  3. [3]

    The activity is attributed to GhostAction, a supply chain campaign that first came to light in September 2025 and impacted 817 repositories across 327 GitHub users, exfiltrating 3,325 secrets including PyPI, npm and DockerHub tokens.

    ReportedSupportedSource: The Hacker NewsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 9, 2026

    Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories