socket-dev · Crawled Oct 9, 2026

New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

3 IoCs
Read original article ↗

AI Summary

A new wave of the GhostAction campaign has compromised maintainer accounts on GitHub, injecting a malicious workflow named security-audit.yml into 346 repositories, including high-profile projects like uber/athenadriver and kitao/pyxel. The workflow exfiltrates both GitHub Actions secrets and cloud/AI service credentials from the working tree and full Git history, sending them to a hardcoded C2 server. This variant expands on prior GhostAction activity by combining stolen publishing credentials with the harvesting of committed cloud credentials, including AWS, OpenAI, and GitHub API keys. The malicious workflow runs on every push and remains active on affected repositories, posing ongoing supply chain and cloud security risks.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 193[.]32[.]204[.]199 Details →
Filename security-audit.yml Details →
Filename github_actions_security.yml Details →