Cyber Security News

Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens

Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks.

The workflows targeted 2,577 secrets, but targeting did not always translate into theft.

Researchers confirmed successful exfiltration of 26 secrets from 13 repositories, highlighting the distinction between malicious injections and executed payloads.

Attackers inserted github_actions_security.yml with the commit message “Add Github Actions Security workflow.”

Configured for push events and manual dispatch, the workflow runs on ubuntu-latest and sends selected secrets through a single curl POST request.

Rather than dumping every environment variable, the attacker apparently examined legitimate workflow files and configuration history for named secret references.

The malicious workflow then explicitly requested those values, including deployment hosts, SSH private keys, and usernames.

The latest payload sends credentials over unencrypted HTTP to 193.32.204.199. A September 7 variant, observed in seven repositories, used security-check.yml and the workflow name “Security Check.”

Its destination, hxxp://193.32.204.199:3000/api/workflow/receive?inj=<id>, included an injection identifier, suggesting backend tracking of individual compromises.

Commits appeared under victims’ identities, consistent with stolen credentials. This reflects abuse of repository access and CI/CD permissions, rather than evidence of a vulnerability in GitHub Actions itself.

SSH keys and deployment credentials accounted for 446 targeted secrets, followed by Azure credentials at 218, container registry credentials at 142, database credentials at 112, and AWS access keys at 106.

GitHub tokens, FTP credentials, Google Cloud keys, and messaging platform tokens were also targeted.

GitGuardian’s latest GhostAction investigation identified, 772 public repositories across 373 GitHub users and organizations compromised between August 31 and September 30, 2026.

Across 605 repositories, researchers collected 3,669 workflow runs. GitHub held most for approval; 499 executed across 32 repositories, and 336 completed successfully.

Legitimate commits made after injection triggered most runs because the malicious workflows remained configured for every push.

GitHub Actions Workflows

Cleanup remained incomplete. Only 124 repositories, approximately 16% of those affected, showed effective remediation in observed public history by October 5.

GhostAction was first documented in September 2025, when GitGuardian reported 817 affected repositories and 3,325 stolen secrets.

The technique subsequently appeared in Shai-Hulud campaigns and remains part of Mini Shai-Hulud’s credential collection capabilities.

In 92 recent cases, attackers updated existing malicious workflows instead of adding files, redirecting older payloads to new infrastructure.

Historical endpoints included carte-avantage.com and 170.39.218.2, demonstrating persistence rather than a cleanly separated revival.

Researchers also found an XMRig cryptominer embedded in kuafuai/DevOpsGPT before its GhostAction compromise.

The scale of the new wave (Source : GitGuardian).

The Dockerfile installed the miner as /usr/local/bin/pyworker, while an encrypted configuration and recurring health_check task concealed and maintained execution.

The same compromised account later injected GhostAction workflows targeting DockerHub credentials.

However, different commit characteristics and project-specific miner modifications left researchers unconvinced that both attacks shared an operator.

Thirteen GhostAction victim repositories also overlapped with at least four distinct cryptomining campaigns.

Related reporting on Shai-Hulud 2.0 documents how stolen tokens can enable credential exfiltration through attacker-controlled GitHub repositories.

Mini Shai-Hulud’s latest wave expanded harvesting to 469 secret locations, illustrating how workflow abuse fits into broader attacks against developer endpoints, cloud services, and automated software delivery pipelines worldwide.

Affected maintainers should remove unauthorized workflows, revoke and rotate exposed credentials, and audit repository access and published artifacts.

Workflow removal alone does not invalidate stolen secrets; response must also address the credentials enabling repeated compromise.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago