Malicious GitHub Actions Workflows Target Developer Credentials Across Repositories

Malicious GitHub Actions Workflows Target Developer Credentials Across Repositories

Cybersecurity researchers have disclosed details of an ongoing credential theft campaign involving malicious GitHub Actions workflows that were inserted into hundreds of repositories through compromised open source maintainer accounts. The activity has been linked to the GhostAction supply chain attack campaign, with researchers reporting that attackers used trusted developer identities to distribute workflows designed to collect sensitive credentials from affected projects. According to StepSecurity, attackers used the account of Takashi Kitao, the creator of the popular open source game engine pyxel, to push a malicious workflow to 27 repositories before later using the account of Henry Wu, the original author of Uber’s athenadriver project, to distribute the same workflow across 318 repositories within a short period. Security firm Socket said it had identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

The campaign follows earlier GhostAction activity first identified in September 2025, when researchers observed attackers targeting software supply chains through compromised developer accounts. Previous investigations found that the campaign affected hundreds of repositories and resulted in the exposure of thousands of secrets, including tokens associated with package registries and developer platforms. In the latest activity, attackers have continued using GitHub Actions workflows disguised as security tools, including files named “security-audit.yml” and “github_actions_security.yml.” Researchers found that these workflows were designed to collect sensitive information and transmit it to an attacker controlled endpoint. The captured information reportedly included GitHub Actions secrets, continuous integration and delivery credentials, cloud service keys, artificial intelligence platform API keys, software development tokens, and credentials stored within repository files or previous git history.

According to StepSecurity, the attack process begins when attackers obtain access to a maintainer’s GitHub credentials, potentially through exposed personal access tokens or previously leaked credentials. After gaining access, the attackers review workflow files and repository contents for sensitive information before adding a malicious workflow under the identity of the compromised account. The injected workflow is designed to run under specific GitHub Actions triggers, including manual execution and repository changes, while using repository checkout settings that allow access to complete git history. Researchers said the workflow performs several activities, including collecting repository secrets, scanning files for credential patterns linked to cloud platforms, AI services, source control systems, and software as a service providers, and searching historical commits for credentials that may have been removed from current files. The workflow also attempts to identify matching cloud access credentials, such as AWS access key pairs, that could provide further access to affected environments.

Additional analysis from GitGuardian found that the GhostAction campaign pushed malicious workflows to hundreds of public repositories belonging to hundreds of GitHub users and organizations between August 31 and September 30, 2026. The targeted credentials reportedly included SSH private keys, cloud service credentials, container registry access details, database credentials, GitHub tokens, communication platform bot tokens, and keys linked to developer ecosystems such as npm, PyPI, and AI service providers. Researchers also identified at least one case where a repository was modified to include an XMRig cryptocurrency mining component within a Docker image, although no malicious software package releases using compromised publishing credentials had been confirmed at the time of reporting. Security teams and developers have been advised to review repositories for the identified malicious workflows, remove unauthorized files, revoke potentially exposed credentials, rotate access keys, and inspect forks or mirrors connected to affected repositories. Researchers warned that downstream forks can remain exposed if they inherit malicious workflows or synchronize with compromised upstream projects, making repository monitoring and credential management essential for reducing further supply chain risks.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment