GBHackers

GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials


A new GhostAction campaign has expanded to more than 500 compromised GitHub accounts and has injected malicious workflows into tens of thousands of repositories since October 7, 2026.

Socket’s October 9 update describes a credential theft operation targeting GitHub Actions secrets, cloud credentials, and AI service API keys embedded in source code and repository history.

An initially analyzed October 8 burst affected 346 repositories through compromised maintainer accounts henrywoo and kitao.

GhostAction Hackers Compromise 500+ GitHub Accounts

Targets included uber/athenadriver and kitao/pyxel, exposing how contributor permissions can extend an account compromise into organization-owned projects. Socket did not determine how attackers obtained the initial maintainer credentials.

Attackers committed .github/workflows/security-audit.yml directly to repository default branches using messages such as “Add security audit workflow.”

Despite its reassuring name, the workflow harvests credentials. It runs on push events without branch or path restrictions and supports manual execution through workflow_dispatch.

Before deployment, attackers apparently inspected existing workflows to identify referenced Action secrets, then inserted those names into a reusable payload.

In Pyxel, the workflow targeted CARGO_REGISTRY_TOKEN, PERSONAL_ACCESS_TOKEN, PYPI_PASSWORD, and PYPI_USERNAME, creating potential exposure across GitHub, PyPI, and crates.io. The uniform payloads and compressed deployment windows suggest automated enumeration and injection.

The new variant adds a repository scanning stage alongside the established Actions secret theft mechanism.

Using actions/checkout@v4 with fetch-depth: 0, it retrieves history across branches and tags, then examines working-tree files and patch output from git log -p --all. Its history buffer is capped at 200,000 lines.

Thirteen credential patterns cover AWS access identifiers, secret keys and session tokens; Anthropic, OpenAI and OpenRouter API keys; GitHub and GitLab tokens; and Google, Slack and SendGrid credentials.

Historical scanning can uncover secrets removed from current files but still retained in reachable commits. The payload also captures two surrounding lines on either side of AWS access key identifiers.

This context can expose adjacent secret access keys, helping attackers recover usable credential combinations rather than isolated identifiers. Collected data and repository identifiers are transmitted together through a cleartext HTTP POST to hxxp://193.32.204[.]199/?c=monami.

Socket confirmed successful workflow runs in affected repositories, with Pyxel providing the clearest publishing-credential targeting example. However, researchers had observed no malicious PyPI or crates.io releases attributable to this activity.

Defenders should remove injected workflows, review execution logs, revoke compromised account access, and rotate exposed credentials. Response must cover both Actions secrets and committed credentials, including historical exposures.

Socket also recommends auditing package releases, reviewing AWS CloudTrail activity, blocking the exfiltration address, enabling secret scanning with push protection, and inspecting affected forks before enabling Actions. Organization-wide checks should follow account permissions.

CategoryIndicatorDescription
Workflow file path.github/workflows/security-audit.ymlMalicious workflow file masquerading as a security audit.
Workflow file path.github/workflows/github_actions_security.ymlAlternative malicious workflow file path.
Commit messageAdd security audit workflowCommit message associated with malicious workflow injection.
Commit messageUpdate security audit workflowCommit message associated with malicious workflow updates.
Commit messageAdd Github Actions Security workflowAlternative commit message associated with workflow injection.
Request body markerREPO=Identifies the repository in the exfiltration request body.
Request body markerAKIA_CTX_STARTMarks the beginning of collected AWS credential context.
Request body markerAKIA_CTX_ENDMarks the end of collected AWS credential context.
Network — C2 IP address193.32.204[.]199Attacker-controlled destination used for credential exfiltration.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 



Source link