What happened
Material escalation of the previously reported GhostAction campaign (which was flagged at 346 repos on Oct 8): StepSecurity and Socket documented a new Oct 7-9 wave in which two prominent maintainer accounts pushed the malicious workflow to 345+ repos in under 16 minutes, and Socket identified 500+ accounts committing it to tens of thousands of repositories. Blast radius now spans private forks/mirrors; one observed case (kuafuai/DevOpsGPT) also had an XMRig miner embedded in its Docker image. This is in-window (Oct 7-10 disclosures, Oct 10 reporting).
Why it matters
This is an active, in-the-wild supply-chain campaign squarely targeting AI developers and their tooling: the malicious workflows explicitly harvest Anthropic, OpenAI and OpenRouter API keys plus cloud credentials from AI-agent/DevOps repositories, and AI repos (DevOpsGPT) are directly modified. Any organization running CI on affected repos is exposed to credential theft that can be turned against LLM spend, model-serving accounts and cloud environments.
Attack vector
Attackers use leaked PATs/infostealer logs to log in as maintainers, commit a malicious GitHub Actions workflow (security-audit.yml / github_actions_security.yml) to the default branch that triggers on workflow_dispatch/push, checks out full history (fetch-depth:0), scans working tree and git history for 13 credential patterns including AWS keys and Anthropic/OpenAI/OpenRouter API keys, pairs AWS key IDs with secrets, and exfiltrates everything over plain HTTP to 193.32.204[.]199.
Affected systems
GitHub Actions workflows in open-source and private repositories of compromised maintainer accounts (e.g. pyxel author Takashi Kitao, Uber athenadriver author Henry Wu), incl. AI-oriented repos like kuafuai/DevOpsGPT
Mitigation
Treat presence of security-audit.yml / github_actions_security.yml since Aug 31, 2026 as compromise: delete the workflow from all branches/forks, revoke the compromised GitHub credential, rotate all secrets incl. AI API keys, review private forks/mirrors. References: https://thehackernews.com/2026/10/credential-stealing-github-actions.html, https://www.stepsecurity.io/blog/ghostaction-returns