Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Holborn and St Pancras byelection loss will disappoint Greens – but there may also be relief | Holborn and St Pancras byelection

    October 9, 2026

    Bragging rights for Burnham, blues for Farage: conference season winners and losers | Politics

    October 9, 2026

    Tesla’s ‘Full Self-Driving’ Becomes ‘Assisted Driving’ in Europe

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Holborn and St Pancras byelection loss will disappoint Greens – but there may also be relief | Holborn and St Pancras byelection
    • Bragging rights for Burnham, blues for Farage: conference season winners and losers | Politics
    • Tesla’s ‘Full Self-Driving’ Becomes ‘Assisted Driving’ in Europe
    • FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack
    • ETH fee burns cover just 2% of new coins printed in 2026
    • Looking for Oil in Alaska, No Environmental Strings Attached
    • 2026 Nobel Peace Prize Goes to Former ICC Judge Navi Pillay, Prompting New U.S. Sanctions
    • Powerful 7.6-magnitude earthquake hits Panama and triggers tsunami warnings | Panama
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories.

    “Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity said. “Eight hours later, the account of Henry Wu (henrywoo), the original author of Uber’s athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window, 21:10–21:26 UTC.”

    As of October 9, 2026, Socket said it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

    The activity has been attributed to GhostAction, a massive supply chain attack campaign that first came to light in September 2025. The activity impacted 817 repositories across 327 GitHub users, resulting in the exfiltration of 3,325 secrets, including PyPI, npm, and DockerHub tokens through compromised developer accounts.

    Like before, both accounts have been found to push a workflow named Security Audit (“security-audit.yml”) or GitHub Actions Security (“github_actions_security.yml”), which are designed to exfiltrate sensitive data to a hard-coded IP address (“193.32.204[.]199”) over plain HTTP.

    The captured data contains the repository’s named GitHub Actions secrets, including CI/CD secrets, and cloud, AI, and SaaS credentials present in the working tree and the entire git history, such as AWS keys, Anthropic, OpenAI, and OpenRouter API keys, and GitHub and GitLab tokens.

    Cybersecurity

    The entire attack chain plays out as follows –

    • The attacker obtains a maintainer’s GitHub credentials, most likely a leaked personal access token (PAT) from infostealer logs or credential dumps.
    • The repository’s workflow files are scanned for secrets as part of a reconnaissance step.
    • A workflow masquerading as a security audit is injected into the default branch under the victim’s own identity.
    • The embedded payload extracts the data and sends it to an attacker-controlled endpoint via curl.

    “It triggers on workflow_dispatch and an unfiltered push (any branch, any tag), checks out with fetch-depth: 0, and runs a single ‘Audit’ step that does four things,” StepSecurity added. This includes –

    • Append the repository’s named secrets found during reconnaissance
    • Scan the working tree for 13 credential patterns associated with AWS keys, AI services, source control services, and SaaS and cloud API keys
    • Check the entire git history for the same 13 patterns to harvest credentials that may have inadvertently committed to the repository and subsequently deleted
    • Pair AWS access key IDs with their matching secret access keys

    Earlier this week, GitGuardian reported that the GhostAction campaign pushed the malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026.

    The injected workflows target 2,577 secrets, including SSH private keys, Azure credentials, DockerHub and GHCR container registry credentials, database credentials, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, Telegram, Slack, and Discord bot tokens, and keys associated with Cloudflare, npm, PyPI, and AI providers.

    Cybersecurity

    In at least one case observed on August 30, 2026, the threat actors altered the “kuafuai/DevOpsGPT” repository to embed an XMRig cryptocurrency miner in the project’s Docker image. As of writing, no malicious package releases have been published using compromised publishing credentials.

    Developers are advised to check their repositories for either of the two GitHub workflows since August 31, 2026, and assume compromise, if present. It’s recommended to revoke the compromised GitHub credential, rotate credentials, delete the malicious workflow from all branches, and check forks of the infected repositories.

    “The 279 forks in the henrywoo namespace each carry the workflow file. If Actions are enabled, subsequent pushes can trigger credential harvesting,” Socket said. “Downstream forks are also at risk if they inherit the malicious workflow, either when newly created or by synchronizing with the affected upstream repository.”

    “Private forks and downstream mirrors are the most exposed, because private repositories are where committed credentials are actually found. Across both accounts, every run also returns a repository identifier whether or not credentials were found, so the operator holds a map of reachable execution contexts independent of any credential theft.”

    Actions CredentialStealing GitHub planted Repositories Tens Thousands Workflows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

    TP-Link Sued by Four More U.S. States Over Router Security and China Ties

    What We Missed: FBI Strikes Back at ShinyHunters

    P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Holborn and St Pancras byelection loss will disappoint Greens – but there may also be relief | Holborn and St Pancras byelection

    October 9, 2026

    Bragging rights for Burnham, blues for Farage: conference season winners and losers | Politics

    October 9, 2026

    Tesla’s ‘Full Self-Driving’ Becomes ‘Assisted Driving’ in Europe

    October 9, 2026

    FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

    October 9, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Holborn and St Pancras byelection loss will disappoint Greens – but there may also be relief | Holborn and St Pancras byelection

    October 9, 2026

    Bragging rights for Burnham, blues for Farage: conference season winners and losers | Politics

    October 9, 2026

    Tesla’s ‘Full Self-Driving’ Becomes ‘Assisted Driving’ in Europe

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.