GhostAction
campaign · campaign:ghostaction
GitHub Actions credential-theft campaign: stolen maintainer credentials commit a fake security workflow straight to default branches, which exfiltrates the repositories' Actions secrets and, since October 2026, credentials found in the working tree and the entire git history; first documented in September 2025 and active again from 2026-08-31 (StepSecurity, Socket and GitGuardian, 2026-10-07 to 2026-10-09).
Action items (1)
Do-now tasks recorded on the entries about GhostAction, newest first. Check the date before acting on an older one.
- Run an organisation-scoped GitHub code search in every organisation your teams and suppliers administer for workflow files under .github/workflows that present themselves as a security audit, a security check or an Actions security workflow and were added since 2026-08-31; any hit means assume breach: revoke the credential that committed it and rotate every secret found anywhere in the repository's git history, not only the configured Actions secrets.2026-10-10GhostAction: fake security workflows now harvest…
Defender insights
What each entry about GhostAction tells a defender to do, newest first.
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
related to
- Mini Shai-HuludGitGuardian says the injected-workflow technique GhostAction used was later reused in the Shai-Hulud campaigns and remains at the core of the Mini Shai-Hulud malware family; a technique-reuse statement, not an attribution
Story timeline
ATT&CK techniques (3 across 6 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Cloud Accounts
- PersistenceValid Accounts: Cloud Accounts
- Privilege EscalationValid Accounts: Cloud Accounts
- StealthValid Accounts: Cloud Accounts
- Credential AccessUnsecured Credentials: Credentials In Files
- ExfiltrationExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Exfiltration TA0010
T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol×1
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗
Entries about GhostAction (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- blog.gitguardian.com1 (33%)
- socket.dev1 (33%)
- stepsecurity.io1 (33%)