
Cybersecurity researchers have disclosed particulars of an ongoing credential-theft marketing campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.
“Utilizing the account of Takashi Kitao, writer of the 18,400-star sport engine pyxel, the attacker pushed a malicious workflow to 27 repositories beginning at 13:20 UTC,” StepSecurity stated. “Eight hours later, the account of Henry Wu (henrywoo), the unique writer of Uber’s athenadriver, was used to push the identical workflow to 318 repositories in a 16-minute window, 21:10–21:26 UTC.”
As of October 9, 2026, Socket stated it has recognized greater than 500 GitHub accounts that dedicated the malicious workflow to tens of hundreds of repositories since October 7, 2026.
The exercise has been attributed to GhostAction, an enormous provide chain assault marketing campaign that first got here to mild in September 2025. The exercise impacted 817 repositories throughout 327 GitHub customers, ensuing within the exfiltration of three,325 secrets and techniques, together with PyPI, npm, and DockerHub tokens by compromised developer accounts.
Like earlier than, each accounts have been discovered to push a workflow named Safety Audit (“security-audit.yml”) or GitHub Actions Safety (“github_actions_security.yml”), that are designed to exfiltrate delicate information to a hard-coded IP tackle (“193.32.204[.]199”) over plain HTTP.
The captured information accommodates the repository’s named GitHub Actions secrets and techniques, together with CI/CD secrets and techniques, and cloud, AI, and SaaS credentials current within the working tree and your complete git historical past, equivalent to AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens.
All the assault chain performs out as follows –
- The attacker obtains a maintainer’s GitHub credentials, most certainly a leaked private entry token (PAT) from infostealer logs or credential dumps.
- The repository’s workflow recordsdata are scanned for secrets and techniques as a part of a reconnaissance step.
- A workflow masquerading as a safety audit is injected into the default department below the sufferer’s personal id.
- The embedded payload extracts the information and sends it to an attacker-controlled endpoint through curl.

“It triggers on workflow_dispatch and an unfiltered push (any department, any tag), checks out with fetch-depth: 0, and runs a single ‘Audit’ step that does 4 issues,” StepSecurity added. This contains –
- Append the repository’s named secrets and techniques discovered throughout reconnaissance
- Scan the working tree for 13 credential patterns related to AWS keys, AI companies, supply management companies, and SaaS and cloud API keys
- Verify your complete git historical past for a similar 13 patterns to reap credentials which will have inadvertently dedicated to the repository and subsequently deleted
- Pair AWS entry key IDs with their matching secret entry keys
Earlier this week, GitGuardian reported that the GhostAction marketing campaign pushed the malicious workflow to 772 public repositories belonging to 373 GitHub customers and organizations between August 31 and September 30, 2026.
The injected workflows goal 2,577 secrets and techniques, together with SSH personal keys, Azure credentials, DockerHub and GHCR container registry credentials, database credentials, AWS entry keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, Telegram, Slack, and Discord bot tokens, and keys related to Cloudflare, npm, PyPI, and AI suppliers.
In at the very least one case noticed on August 30, 2026, the menace actors altered the “kuafuai/DevOpsGPT” repository to embed an XMRig cryptocurrency miner within the undertaking’s Docker picture. As of writing, no malicious package deal releases have been revealed utilizing compromised publishing credentials.
Builders are suggested to examine their repositories for both of the 2 GitHub workflows since August 31, 2026, and assume compromise, if current. It is really useful to revoke the compromised GitHub credential, rotate credentials, delete the malicious workflow from all branches, and examine forks of the contaminated repositories.
“The 279 forks within the henrywoo namespace every carry the workflow file. If Actions are enabled, subsequent pushes can set off credential harvesting,” Socket stated. “Downstream forks are additionally in danger in the event that they inherit the malicious workflow, both when newly created or by synchronizing with the affected upstream repository.”
“Personal forks and downstream mirrors are essentially the most uncovered, as a result of personal repositories are the place dedicated credentials are literally discovered. Throughout each accounts, each run additionally returns a repository identifier whether or not or not credentials had been discovered, so the operator holds a map of reachable execution contexts impartial of any credential theft.”

