Vulnerability  ·  2026-10-11

GhostAction GitHub Actions supply-chain campaign resurges: 346+ repos hit Oct 8, stealing CI/CD and AI-API credentials

VulnerabilityHigh impactGlobal
The GhostAction supply-chain campaign, first documented in Sep 2025, did not stop: between Aug 31 and Sep 30 2026 it injected credential-stealing workflows into 772 public repositories, and a fresh burst on Oct 8 targeted 346 more repos in two automated sweeps lasting minutes. Exfiltration targets include SSH keys, cloud (Azure/AWS/GCP) credentials, container registry creds and AI-provider/API keys; only 16% of affected repos had been cleaned by Oct 5.
This is an active mass supply-chain campaign against AI/ML developer tooling: the steal list explicitly includes AI provider API keys and cloud credentials from developer machines and CI/CD, and it operates through the same trusted-workflow technique family (Shai-Hulud/Mini Shai-Hulud) seen in AI-developer targeting. It has no CVE and would be missed by NVD-driven coverage.
Threat actors using previously stolen maintainer credentials push a malicious 'security audit' workflow into victim repositories. The workflow references secret names scraped from each repo's existing workflows and POSTs their values (SSH keys, Azure/AWS/GCP credentials, database creds, npm/PyPI tokens, AI provider API keys) to attacker infrastructure (193.32.204.199). The Oct 8 wave also sweeps working tree and full git history for cloud/AI credentials, and runs actually executed and exfiltrated.
GitHub repositories and GitHub Actions runners; compromised maintainer accounts; injected security-audit.yml / github_actions_security.yml / security-check.yml workflows
Audit repos for injected security-audit.yml/github_actions_security.yml/security-check.yml workflows; review recently merged workflow changes from compromised accounts; revoke all secrets that touched affected repos; enable approval gates on workflow runs and require PR-based changes to .github/workflows; rotate maintainer credentials. See GitGuardian and Socket analyses.
GitGuardian — GhostAction returnsStepSecurity — GhostAction returnsThe Hacker News — credential-stealing GitHub Actions
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →