step-security · Crawled Oct 9, 2026
GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories
9 IoCs
Read original article ↗
AI Summary
The GhostAction campaign has resurged with a new wave of malicious GitHub Actions workflows injected into compromised open-source repositories. Attackers compromised maintainer accounts (kitao, henrywoo) to push malicious 'security audit' workflows directly to default branches, bypassing review. These workflows exfiltrate GitHub Actions secrets and mine the entire git history for credentials, including AWS, AI provider, and SaaS tokens. The exfiltration endpoint has shifted to the IP address 193.32.204.199, using plain HTTP to evade domain-based detection. Successful exfiltration was confirmed in multiple repositories, including Uber's athenadriver.
AI-extracted · verify before operational use
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 193[.]32[.]204[.]199 | Details → |
| IP | 45[.]139[.]104[.]115 | Details → |
| IP | 170[.]39[.]218[.]2 | Details → |
| Domain | bold-dhawan[.]45-139-104-115[.]plesk[.]page | Details → |
| Domain | carte-avantage[.]com | Details → |
| Domain | *[.]oast[.]fun | Details → |
| Filename | .github/workflows/security-audit.yml | Details → |
| Filename | .github/workflows/github_actions_security.yml | Details → |
| Filename | .github/workflows/security-check.yml | Details → |