GhostAction Returns: Hijacked Maintainer Accounts Mine Git History for Cloud and AI Keys
Attackers hijacked two popular open-source maintainer accounts and pushed a fake 'security audit' workflow to hundreds of repositories, scraping secrets from CI and from full git history.
The credential-theft campaign known as GhostAction is back, and this time it reads your entire git history. On 8 October 2026 its operators took over two well-known open-source maintainer accounts and used them to commit a malicious GitHub ActionsGitHub Actions🛡️GitHub's built-in automation and CI/CD platform. It runs workflows defined in YAML files under a repository's .github/workflows directory, and those jobs can read the repository's stored secrets and reach the network. workflow to every repository those accounts could write to. The workflow calls itself a security audit. It does nothing of the sort.
What Happened
The first hijacked account belonged to Takashi Kitao, author of the retro game engine pyxel, which carries more than 18,000 GitHub stars. Starting at 13:20 UTC the attackers pushed a workflow file to 27 of his repositories. Later the same day, between 21:10 and 21:26 UTC, they used the account of Henry Wu, the original author of Uber's athenadriver, to push the same workflow to 318 repositories, 39 of them source projects and the rest forks. Across the two accounts, roughly 345 repositories were seeded in two bursts that each lasted only minutes.
That was the visible tip. Socket, which tracked the activity in parallel, reports more than 500 compromised GitHub accounts committing the same workflow to tens of thousands of repositories since 7 October 2026.
The "Security Audit" Workflow
In each repository the attackers added a single file, a workflow named `security-audit.yml`, under commit messages such as "Add security audit workflow" and "Update security audit workflow." Earlier waves used the filenames `github_actions_security.yml` and `security-check.yml`; all three belong to the same family. The workflow performs no security function. It exists only to collect secrets and send them to an attacker-controlled server.
It runs on any push and can also be triggered by hand. Once it executes on GitHub's own runners, it harvests credentials in four stages. First it reads the repository's named Actions secrets, templated in advance from reconnaissance of each project's real pipelines, with names such as `PYPI_PASSWORD`, `CARGO_REGISTRY_TOKEN` and `PERSONAL_ACCESS_TOKEN`. Second it sweeps the checked-out working tree with regular expressions tuned to thirteen credential formats. Third, and this is the dangerous addition, it checks out the full commit history with a fetch depth of zero and runs a history-wide log scan, reading every diff on every branch and tag. That recovers secrets that were committed and later deleted, credentials most teams assume are long gone. Fourth it captures the lines around any Amazon Web Services access-key match, wrapping them in start and end markers so the operators can pair an access-key ID with its matching secret key.
Understanding why a build runner can reach all of this at once is worth its own read; see how a GitHub Actions workflow can reach every secret in your pipeline.
The regex set targets AWS keys, GitHub and GitLab tokens, Google and Firebase keys, Slack and SendGrid tokens, and, new in this wave, AI provider keys for Anthropic, OpenAI and OpenRouter. The stolen data is sent by plain HTTP POST to a bare IP addressIP Address🔐A unique numerical identifier assigned to every device connected to the internet., 193.32.204.199, with in-band markers so the operators can sort what arrives: one tag for repositories that yielded named secrets and another for history-sweep results. StepSecurity confirmed one successful exfiltration from the athenadriver repository, where the server acknowledged the data four seconds after the workflow started. That same IP is also being used as an active internet scanner, per GreyNoise and Shodan telemetry.
What Is Different This Time
GhostAction first surfaced in September 2025, when GitGuardian found malicious workflows in 817 repositories across 327 users and counted 3,325 stolen secrets. A wave running from late August to late September 2026 hit 772 repositories and 373 users and organisations, targeting 2,577 secrets; in that round GitHub held most of the malicious runs for manual approval, which blunted the damage.
The October wave is worse for four reasons. It mines full git history, so rotating a secret out of the current tree is no longer enough. It treats AI API keys as first-class loot, reflecting how much production spend now sits behind model-provider billing. It reconstructs complete AWS key pairs rather than grabbing loose fragments. And it exfiltrates to a raw IP over plain HTTP, sidestepping defences that depend on blocking known-bad domains.
Who Is Affected
Any organisation that depends on a project maintained by a compromised account is exposed, and the fork mechanic widens the blast radiusBlast Radius🛡️The full set of systems, data, and access an attacker can reach after compromising a given asset. Ranking assets by blast radius rather than by how exposed they are pushes high-reach systems like a firewall management console to the top of the priority list.: a malicious workflow in a popular project is inherited by its forks, and private forks and downstream mirrors carry the highest risk because they often hold live credentials and escape public scanning.
The initial access was not a flaw in GitHub. StepSecurity assesses that the maintainer accounts were most plausibly taken over with a leaked personal access tokenAccess Token🛡️A credential issued by an authorization server that grants an application temporary access to specific resources on behalf of a user. pulled from infostealerInfostealer🛡️Malware that harvests credentials, session cookies, tokens and other secrets from an infected machine and sells or dumps them. Leaked developer tokens from infostealer logs are a common way accounts get hijacked. logs or credential dumps. Researchers also flagged lookalike phishingPhishing🛡️A social engineering attack using fake emails or websites to steal login credentials or personal info. domains, my-gitlab.com registered on 22 September and my-github.com registered on 9 October, which points to credential phishing as part of the operation.
Immediate Actions
Treat any workflow named `security-audit.yml` or `github_actions_security.yml` added to your repositories since 31 August 2026 as a confirmed breach, not a curiosity. A GitHub code search for the string `193.32.204.199` inside `.github/workflows` surfaced hundreds of live instances; searches for the AWS context marker and the named-secret tag find the two payload variants.
If you find one, revoke rather than merely rotate the GitHub credential that pushed it, and kill the account's sessions, because a rotated-but-reused token gets used again. Rotate every Actions secret and every credential ever committed to the repository, because the attacker read your history, not just your current files. That is the hard part, and it is exactly why you want a worked process for how to find and remove secrets hidden in your git history before you ever need one. Delete the workflow from every branch, not just the default, audit forks for the inherited copy, and review package-registry history on PyPI, crates.io and npm for releases you did not publish during the exposure window.
Long-Term Outlook
GhostAction works because most CI systems hand a workflow broad, standing access to long-lived secrets, and because one stolen maintainer token can rewrite the pipelines of hundreds of downstream projects at once. The durable fix is architectural, and it is the subject of why short-lived credentials beat rotating secrets after a CI breach: move from stored secrets toward identity-based, short-lived credentials, gate workflow execution behind approvals, and restrict what a runner can reach on the network. The same lesson that made a long-lived CDN API key the most dangerous secret in your codebase applies to every token your build touches.
Supply-chain compromise through the build system is now a mainstream attack pattern, and the maintainer account has become critical infrastructure. The projects hit here were not careless. They were popular. That is the point.
Sources
- StepSecurity, "GhostAction Returns: Malicious 'Security Audit' Workflows Now Mine Credentials from Entire Git Histories" (https://www.stepsecurity.io/blog/ghostaction-returns)
- Socket, "New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials" (https://socket.dev/blog/ghostaction-cloud-credentials)
- GitGuardian, "GhostAction Returns: 772 Repos Hit in New GitHub Actions Wave" (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack-returns/)
- GitGuardian, "The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows" (https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/)
- The Hacker News, "Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories" (https://thehackernews.com/2026/10/credential-stealing-github-actions.html)