Researchers uncovered an ongoing GhostAction credential-theft campaign that hijacked maintainer accounts to inject malicious GitHub Actions workflows into hundreds of repositories. The attack exfiltrates secrets and credentials from repositories and git history, affecting projects tied to Takashi Kitao, Henry Wu, and the kuafuai/DevOpsGPT repository. #GhostAction #TakashiKitao #HenryWu #pyxel #athenadriver #kuafuaiDevOpsGPT
Keypoints
- GhostAction used compromised maintainer accounts to push malicious workflows.
- More than 500 GitHub accounts were linked to the campaign by October 9, 2026.
- The workflows exfiltrate secrets to a hard-coded IP address over plain HTTP.
- The attack targets GitHub Actions secrets, cloud credentials, API keys, and tokens.
- Developers should remove the workflow, rotate credentials, and inspect forks and mirrors.
Read More: https://thehackernews.com/2026/10/credential-stealing-github-actions.html