Skip to content

GhostAction supply-chain attack returns, hits 340+ repos

The GhostAction campaign is back: malicious GitHub Actions workflows pushed to 340+ repos via two hijacked maintainer accounts, exfiltrating secrets to a hard-coded IP over plain HTTP.

Published 3 min read

The GhostAction supply-chain campaign is back. According to a StepSecurity report, attackers used two hijacked open-source maintainer accounts to push a malicious GitHub Actions workflow into more than 340 repositories, then used it to steal credentials from the build environment and the checked-out code.

What happened

StepSecurity traced two pushes from compromised maintainer accounts:

  • The account of Takashi Kitao, author of the 18,400-star pyxel game engine, pushed the workflow to 27 repositories starting at 13:20 UTC.
  • Eight hours later, the account of Henry Wu (henrywoo), original author of Uber's athenadriver, pushed it to 318 repositories in a 16-minute window (21:10–21:26 UTC).

The malicious file lands as security-audit.yml or github_actions_security.yml — a single "Audit" step that runs on workflow_dispatch and on unfiltered pushes, then curls harvested data to an attacker endpoint. It targets named GitHub Actions secrets plus credentials matching a set of patterns in the working tree and git history: AWS access-key pairs, AI-service keys (Anthropic, OpenAI, OpenRouter), and GitHub/GitLab tokens.

Scope

The blast radius is still being sized. Socket reports more than 500 GitHub accounts have committed the workflow to tens of thousands of repositories since October 7. GitGuardian counts 772 public repositories across 373 users and organisations and a broader secret list — SSH keys, Azure, DockerHub/GHCR, database, Google Cloud/Firebase, chat-bot tokens, and npm/PyPI keys.

Socket flags forks as the quiet exposure: the 279 forks in the henrywoo namespace each carry the workflow file, and downstream forks can inherit it through creation or sync.

Indicators

StepSecurity's reporting cites a hard-coded exfiltration endpoint (defanged):

193.32.204[.]199   (plain HTTP)
Workflow filenames: security-audit.yml, github_actions_security.yml

Action checklist

  1. Search every repository and fork for security-audit.yml and github_actions_security.yml committed since August 31. Treat any match as a compromise.
  2. Revoke the GitHub credential used on affected repos, rotate all secrets those repos could reach, and delete the workflow from every branch.
  3. Check forks and mirrors — Socket notes forks inherit the file.
  4. Block or alert on egress to 193.32.204.199 and audit for outbound curl from Actions runners.

Context

GhostAction is not new. StepSecurity dates the original campaign to September 2025, when it hit 817 repositories across 327 users and exposed 3,325 secrets. This is the same playbook — hijack a trusted maintainer, push a self-exfiltrating workflow, let the fork graph spread it — now aimed at AI-service keys alongside the usual cloud credentials, and it arrives the same week another actor was caught slipping credential-stealing steps into a Claude Code GitHub Action. CI secrets remain the softest target in the software supply chain: they're long-lived, broadly scoped, and sitting one compromised maintainer away from the attacker.

Related stories