Credential-stealing GitHub Actions workflows planted in tens of thousands of repositories
Attackers using hijacked maintainer accounts are pushing fake 'security audit' GitHub Actions workflows that harvest cloud, AI and source-control secrets, The Hacker News reported.
At a glance
- Socket says more than 500 GitHub accounts have committed the malicious workflow to tens of thousands of repositories since October 7.
- The workflows, named security-audit.yml or github_actions_security.yml, exfiltrate secrets over plain HTTP to a hard-coded IP address.
- Targeted secrets include AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens.
- Maintainers should look for the workflow files, revoke the hijacked credential and rotate every secret that may have been exposed.
An ongoing supply chain campaign is planting credential-stealing GitHub Actions workflows into open-source repositories through hijacked maintainer accounts, The Hacker News reported on October 9. According to the publication, the activity is tied to the GhostAction operation, and security firm Socket says more than 500 GitHub accounts have committed the malicious workflow to tens of thousands of repositories since October 7, 2026.
What happened
StepSecurity documented two incidents involving compromised accounts, according to the report. In the first, an attacker used the account of Takashi Kitao, author of the popular pyxel game engine, to push the workflow to 27 repositories. About eight hours later, the account of Henry Wu, the original author of Uber's athenadriver, was used to push the same workflow to 318 repositories within a 16-minute window.
The Hacker News also cited GitGuardian, which observed 772 public repositories belonging to 373 users and organizations being targeted between August 31 and September 30, 2026. As of the article's writing, no malicious package releases had been published using stolen publishing credentials.
Technical details
The malicious files are named security-audit.yml or github_actions_security.yml to pass as legitimate security tooling. They run on manual dispatch and on pushes to any branch or tag, check out the full git history and, in a single step, gather named GitHub Actions secrets and scan the working tree and history for 13 credential patterns. The collected data is sent over plain HTTP to a hard-coded IP address, according to the report.
Targeted secrets include AWS access keys paired with their secret keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens. GitGuardian's broader view of GhostAction also covers SSH keys, Azure and Google Cloud credentials, container registry, database and npm or PyPI publishing secrets.
The attackers most likely obtain maintainers' credentials from leaked personal access tokens found in infostealer logs or credential dumps, The Hacker News said. In one case dated August 30, the kuafuai/DevOpsGPT repository was altered to embed an XMRig cryptocurrency miner in its Docker image.
Who is affected
Socket warned that the 279 forks in the henrywoo namespace each carry the workflow and could harvest credentials on later pushes if Actions are enabled. Private forks and downstream mirrors are particularly exposed, because private repositories are where committed credentials are most often found. Every run also reports a repository identifier back to the operator, giving them a map of reachable execution environments.
What to do
The report advises maintainers to check their repositories for either workflow file in changes made since August 31, 2026, and to assume compromise if one is present. Affected users should revoke the hijacked GitHub credential, rotate all cloud, AI and SaaS keys that may have been exposed, delete the workflow from every branch, and review forks and mirrors of infected repositories, especially private ones. Restricting which workflows can run and using short-lived tokens can further reduce exposure.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



