Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks.
The workflows targeted 2,577 secrets, but targeting did not always translate into theft.
Researchers confirmed successful exfiltration of 26 secrets from 13 repositories, highlighting the distinction between malicious injections and executed payloads.
Attackers inserted github_actions_security.yml with the commit message “Add Github Actions Security workflow.”
Configured for push events and manual dispatch, the workflow runs on ubuntu-latest and sends selected secrets through a single curl POST request.
Rather than dumping every environment variable, the attacker apparently examined legitimate workflow files and configuration history for named secret references.
The malicious workflow then explicitly requested those values, including deployment hosts, SSH private keys, and usernames.
The latest payload sends credentials over unencrypted HTTP to 193.32.204.199. A September 7 variant, observed in seven repositories, used security-check.yml and the workflow name “Security Check.”
Its destination, hxxp://193.32.204.199:3000/api/workflow/receive?inj=<id>, included an injection identifier, suggesting backend tracking of individual compromises.
Commits appeared under victims’ identities, consistent with stolen credentials. This reflects abuse of repository access and CI/CD permissions, rather than evidence of a vulnerability in GitHub Actions itself.
SSH keys and deployment credentials accounted for 446 targeted secrets, followed by Azure credentials at 218, container registry credentials at 142, database credentials at 112, and AWS access keys at 106.
GitHub tokens, FTP credentials, Google Cloud keys, and messaging platform tokens were also targeted.
GitGuardian’s latest GhostAction investigation identified, 772 public repositories across 373 GitHub users and organizations compromised between August 31 and September 30, 2026.
Across 605 repositories, researchers collected 3,669 workflow runs. GitHub held most for approval; 499 executed across 32 repositories, and 336 completed successfully.
Legitimate commits made after injection triggered most runs because the malicious workflows remained configured for every push.
Cleanup remained incomplete. Only 124 repositories, approximately 16% of those affected, showed effective remediation in observed public history by October 5.
GhostAction was first documented in September 2025, when GitGuardian reported 817 affected repositories and 3,325 stolen secrets.
The technique subsequently appeared in Shai-Hulud campaigns and remains part of Mini Shai-Hulud’s credential collection capabilities.
In 92 recent cases, attackers updated existing malicious workflows instead of adding files, redirecting older payloads to new infrastructure.
Historical endpoints included carte-avantage.com and 170.39.218.2, demonstrating persistence rather than a cleanly separated revival.
Researchers also found an XMRig cryptominer embedded in kuafuai/DevOpsGPT before its GhostAction compromise.
The Dockerfile installed the miner as /usr/local/bin/pyworker, while an encrypted configuration and recurring health_check task concealed and maintained execution.
The same compromised account later injected GhostAction workflows targeting DockerHub credentials.
However, different commit characteristics and project-specific miner modifications left researchers unconvinced that both attacks shared an operator.
Thirteen GhostAction victim repositories also overlapped with at least four distinct cryptomining campaigns.
Related reporting on Shai-Hulud 2.0 documents how stolen tokens can enable credential exfiltration through attacker-controlled GitHub repositories.
Mini Shai-Hulud’s latest wave expanded harvesting to 469 secret locations, illustrating how workflow abuse fits into broader attacks against developer endpoints, cloud services, and automated software delivery pipelines worldwide.
Affected maintainers should remove unauthorized workflows, revoke and rotate exposed credentials, and audit repository access and published artifacts.
Workflow removal alone does not invalidate stolen secrets; response must also address the credentials enabling repeated compromise.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…