step-security · Crawled Oct 9, 2026

GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories

9 IoCs
Read original article ↗

AI Summary

The GhostAction campaign has resurged with a new wave of malicious GitHub Actions workflows injected into compromised open-source repositories. Attackers compromised maintainer accounts (kitao, henrywoo) to push malicious 'security audit' workflows directly to default branches, bypassing review. These workflows exfiltrate GitHub Actions secrets and mine the entire git history for credentials, including AWS, AI provider, and SaaS tokens. The exfiltration endpoint has shifted to the IP address 193.32.204.199, using plain HTTP to evade domain-based detection. Successful exfiltration was confirmed in multiple repositories, including Uber's athenadriver.

AI-extracted · verify before operational use

Indicators of Compromise 9 extracted

Type Value Detail
IP 193[.]32[.]204[.]199 Details →
IP 45[.]139[.]104[.]115 Details →
IP 170[.]39[.]218[.]2 Details →
Domain bold-dhawan[.]45-139-104-115[.]plesk[.]page Details →
Domain carte-avantage[.]com Details →
Domain *[.]oast[.]fun Details →
Filename .github/workflows/security-audit.yml Details →
Filename .github/workflows/github_actions_security.yml Details →
Filename .github/workflows/security-check.yml Details →