Full Report
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Analysis Summary
# Incident Report: GhostAction Supply Chain Credential Theft Campaign
## Executive Summary
A massive credential-theft campaign, attributed to the threat actor "GhostAction," compromised high-profile open-source maintainer accounts to inject malicious GitHub Actions workflows into tens of thousands of repositories. The attack aimed to exfiltrate CI/CD secrets, cloud credentials, and AI provider API keys to an external server. While no malicious packages have been published yet, the scope involves over 500 compromised accounts and thousands of affected repositories.
## Incident Details
- **Discovery Date:** October 7, 2026 (Recent activity spike)
- **Incident Date:** Ongoing; active phase started August 31, 2026
- **Affected Organization:** GitHub (Maintainers and Organizations)
- **Sector:** Technology / Software Development (Open Source)
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** August 31 – September 30, 2026 (Initial wave); October 7, 2026 (Massive escalation).
- **Vector:** Likely leaked Personal Access Tokens (PATs) obtained via infostealer logs or credential dumps.
- **Details:** The attacker gained control of maintainer accounts, including Takashi Kitao (Pyxel) and Henry Wu (athenadriver).
### Lateral Movement
- **Details:** The attacker used compromised accounts to commit malicious code to hundreds of repositories under the victims' namespaces. In one instance, 318 repositories were compromised in a single 16-minute window (21:10–21:26 UTC).
### Data Exfiltration/Impact
- **Details:** Malicious workflows (`security-audit.yml` or `github_actions_security.yml`) scanned repositories and git history for 13 credential patterns (AWS, OpenAI, etc.) and sent them to a remote IP via `curl`.
### Detection & Response
- **How it was discovered:** Identified by cybersecurity firms StepSecurity, Socket, and GitGuardian through workflow monitoring.
- **Response actions taken:** Public disclosure of Indicators of Compromise (IoCs); researchers advised maintainers to revoke tokens and rotate secrets.
## Attack Methodology
- **Initial Access:** Valid accounts (via compromised PATs/Credentials).
- **Persistence:** Injection of malicious YAML workflow files into the default branch.
- **Privilege Escalation:** Not applicable; used existing maintainer permissions.
- **Defense Evasion:** Masquerading malicious files as "Security Audits"; using plain HTTP for exfiltration.
- **Credential Access:** Scanning repository secrets, environment variables, and full git history for hardcoded keys.
- **Discovery:** Automated reconnaissance of repository workflow files for named secrets.
- **Lateral Movement:** Automated commits across multiple repositories owned by the compromised user.
- **Collection:** Gathering AWS, AI (OpenAI/Anthropic), and SaaS tokens.
- **Exfiltration:** Data sent via `curl` to an attacker-controlled endpoint.
- **Impact:** Potential supply chain compromise; crypto-mining (XMRig) observed in at least one instance.
## Impact Assessment
- **Financial:** High potential cost due to cloud credential theft and potential unauthorized resource usage.
- **Data Breach:** Thousands of secrets exfiltrated, including SSH keys and API tokens for major cloud providers.
- **Operational:** Disruption to CI/CD pipelines and manual remediation required for thousands of repositories.
- **Reputational:** Significant damage to the trust of high-profile open-source projects.
## Indicators of Compromise
- **Network indicators:** `193.32.204[.]199` (Exfiltration endpoint)
- **File indicators:**
- `security-audit.yml`
- `github_actions_security.yml`
- **Behavioral indicators:** Unexpected commits to the default branch using `workflow_dispatch` or unfiltered push triggers; `fetch-depth: 0` used in workflows to pull entire history.
## Response Actions
- **Containment measures:** Deletion of malicious workflow files from all branches and forks.
- **Eradication steps:** Revocation of compromised Personal Access Tokens (PATs).
- **Recovery actions:** Rotation of all potentially exposed secrets (AWS, NPM, PyPI, etc.).
## Lessons Learned
- **Key takeaways:** Attackers are increasingly targeting the developer's identity to bypass traditional security perimeters.
- **Weaknesses:** Reliance on PATs without sufficient expiration or scoping policies allowed for broad lateral movement across repositories.
## Recommendations
- **MFA:** Enforce Mandatory Multi-Factor Authentication for all GitHub maintainers.
- **Token Security:** Transition from PATs to Fine-Grained Personal Access Tokens with limited scopes and short expiration dates.
- **Secret Scanning:** Implement automated tools to detect and block secrets before they are committed to the git history.
- **Workflow Monitoring:** Audit new GitHub Action additions, particularly those requesting high-level permissions or full git history.