Vulnerability  ·  2026-10-12

GhostAction GitHub Actions supply-chain campaign escalates: 500+ accounts / tens of thousands of repos, targeting AI API keys (OpenAI, Anthropic, OpenRouter)

VulnerabilityHigh impactGlobal
Material escalation of the previously reported GhostAction campaign (which was flagged at 346 repos on Oct 8): StepSecurity and Socket documented a new Oct 7-9 wave in which two prominent maintainer accounts pushed the malicious workflow to 345+ repos in under 16 minutes, and Socket identified 500+ accounts committing it to tens of thousands of repositories. Blast radius now spans private forks/mirrors; one observed case (kuafuai/DevOpsGPT) also had an XMRig miner embedded in its Docker image. This is in-window (Oct 7-10 disclosures, Oct 10 reporting).
This is an active, in-the-wild supply-chain campaign squarely targeting AI developers and their tooling: the malicious workflows explicitly harvest Anthropic, OpenAI and OpenRouter API keys plus cloud credentials from AI-agent/DevOps repositories, and AI repos (DevOpsGPT) are directly modified. Any organization running CI on affected repos is exposed to credential theft that can be turned against LLM spend, model-serving accounts and cloud environments.
Attackers use leaked PATs/infostealer logs to log in as maintainers, commit a malicious GitHub Actions workflow (security-audit.yml / github_actions_security.yml) to the default branch that triggers on workflow_dispatch/push, checks out full history (fetch-depth:0), scans working tree and git history for 13 credential patterns including AWS keys and Anthropic/OpenAI/OpenRouter API keys, pairs AWS key IDs with secrets, and exfiltrates everything over plain HTTP to 193.32.204[.]199.
GitHub Actions workflows in open-source and private repositories of compromised maintainer accounts (e.g. pyxel author Takashi Kitao, Uber athenadriver author Henry Wu), incl. AI-oriented repos like kuafuai/DevOpsGPT
Treat presence of security-audit.yml / github_actions_security.yml since Aug 31, 2026 as compromise: delete the workflow from all branches/forks, revoke the compromised GitHub credential, rotate all secrets incl. AI API keys, review private forks/mirrors. References: https://thehackernews.com/2026/10/credential-stealing-github-actions.html, https://www.stepsecurity.io/blog/ghostaction-returns
The Hacker News — Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of RepositoriesStepSecurity — GhostAction ReturnsSocket — GhostAction: Cloud Credentials Stolen from GitHub Actions
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →