CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

GhostAction

campaign · campaign:ghostaction

GitHub Actions credential-theft campaign: stolen maintainer credentials commit a fake security workflow straight to default branches, which exfiltrates the repositories' Actions secrets and, since October 2026, credentials found in the working tree and the entire git history; first documented in September 2025 and active again from 2026-08-31 (StepSecurity, Socket and GitGuardian, 2026-10-07 to 2026-10-09).

Coverage
1
first 2026-10-10 → last 2026-10-10
Latest activity
2026-10-10
GhostAction: fake security workflows now harvest whole git histories; rotating Actions secrets is not enough
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
3
3 hosts

Action items (1)

Do-now tasks recorded on the entries about GhostAction, newest first. Check the date before acting on an older one.

  • Run an organisation-scoped GitHub code search in every organisation your teams and suppliers administer for workflow files under .github/workflows that present themselves as a security audit, a security check or an Actions security workflow and were added since 2026-08-31; any hit means assume breach: revoke the credential that committed it and rotate every secret found anywhere in the repository's git history, not only the configured Actions secrets.
    2026-10-10GhostAction: fake security workflows now harvest…

Defender insights

What each entry about GhostAction tells a defender to do, newest first.

2026-10-10NOTABLEGhostAction: fake security workflows now harvest whole git histories; rotating Actions secrets is not enough

Exposure · triage · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

related to

Story timeline

  1. 2026-10-10GhostAction returns: stolen maintainer credentials push a fake security-audit workflow into the victims' own GitHub repositories, which now harvests credentials from the entire git history
    active-threatsGhostAction: fake security workflows now harvest whole git histories; rotating Actions secrets is not enough

Hunting pivots

Affected products
ATT&CK techniques (3 across 6 tactics)

3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts: Cloud Accounts
  • PersistenceValid Accounts: Cloud Accounts
  • Privilege EscalationValid Accounts: Cloud Accounts
  • StealthValid Accounts: Cloud Accounts
  • Credential AccessUnsecured Credentials: Credentials In Files
  • ExfiltrationExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Exfiltration TA0010

T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol×1

Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Evidence: 2026-10-10/ghostaction-fake-audit-workflow-git-history-credential-theft · ATT&CK page ↗

Entries about GhostAction (1)

2026-10-10 · view entry permalink →

NOTABLENATOB1

GhostAction returns: stolen maintainer credentials push a fake security-audit workflow into the victims' own GitHub repositories, which now harvests credentials from the entire git history

StepSecurity reports that on 2026-10-08 the GhostAction GitHub Actions credential-theft campaign used the accounts of two open-source maintainers to push a workflow disguised as a security improvement to 345 repositories in two automated sweeps, among them an Uber-owned repository that one maintainer could still write to (StepSecurity, 2026-10-09); Socket's independent analysis counts 346 (Socket, 2026-10-09). The operator holds a maintainer's GitHub credential, which StepSecurity assesses as most plausibly a personal access token leaked through infostealer logs or credential dumps, then commits a workflow titled to look like a security audit straight to the default branch under the victim's own identity, unsigned and without a pull request; that push runs it, and nothing in an audit log looks anomalous unless the content is read (StepSecurity, 2026-10-09). GitGuardian says the technique was later reused in the Shai-Hulud campaigns and remains at the core of the Mini Shai-Hulud malware family (GitGuardian, 2026-10-07).

The newer payload sends the named Actions secrets and every cloud, AI-provider and SaaS credential pattern found in the working tree and the entire git history to a hardcoded address over plain HTTP, so no DNS lookup occurs (StepSecurity, 2026-10-09). StepSecurity saw the attacker's server acknowledge the request four seconds into the run at the Uber-owned repository (StepSecurity, 2026-10-09); neither it nor Socket has seen a malicious package release from the stolen credentials yet (Socket, 2026-10-09; StepSecurity, 2026-10-09). A Socket update line claims more than 500 accounts and tens of thousands of repositories since 7 October without a method, against 346 for the 8 October burst in its own body and 378 live-workflow repositories across all waves in StepSecurity's code search of 2026-10-09, so the larger figure stays unconfirmed (Socket, 2026-10-09; StepSecurity, 2026-10-09).

Triage: the audit-log pattern separates this from a team adding a scanning workflow: no pull request, unsigned commits across many repositories, and a manual dispatch right after creation (StepSecurity, 2026-10-09).

confirms the exfiltration completed successfully: the attacker's server acknowledged receipt four seconds after the workflow started

Nothing in an audit log looks anomalous unless the workflow content itself is inspected

The approval gate is worth singling out: it is the single control observed stopping this campaign's exfiltration this week.

StepSecurity 2026-10-09

Socket has observed no malicious package versions published to PyPI or crates.io as a result of this activity at the time of writing.

Socket 2026-10-09

Rotating the secrets exfiltrated by the malicious workflow is not enough. The GitHub credential that allowed the injection in the first place must be found and revoked too, or someone else will use it again.

GitGuardian 2026-10-07

Builds on: CloudSEK: a Gentlemen affiliate reached victims through stolen GitLab CI/CD secrets and drove… · Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build…

threat10 Oct 03:52Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • blog.gitguardian.com1 (33%)
  • socket.dev1 (33%)
  • stepsecurity.io1 (33%)