Wire Observer.
Technology

GhostAction Campaign Hijacks Hundreds of GitHub Repos to Exfiltrate CI/CD Secrets

GhostAction Campaign Hijacks Hundreds of GitHub Repos to Exfiltrate CI/CD Secrets

A fresh wave of the GhostAction supply‑chain attack has been traced to more than 770 public repositories on GitHub, where malicious workflow files were used to siphon credentials from continuous‑integration and delivery pipelines.

The operation spanned the month of September 2026, beginning on August 31 and concluding on September 30, according to analysis published by cybersecuritynews. Researchers identified 772 repositories that hosted counterfeit GitHub Actions workflow definitions designed to run automatically when a project’s CI/CD process was triggered.

These counterfeit workflows exploit the trust model of GitHub Actions: when a workflow file is added to a repository, the platform automatically provisions short‑lived tokens that grant the workflow access to repository secrets. By embedding code that captures those tokens and forwards them to external servers, the attackers were able to harvest a total of 2,577 secrets, including API keys, cloud service credentials, and deployment tokens.

The stolen secrets give threat actors the ability to impersonate legitimate build agents, push malicious code to downstream projects, or gain unauthorized access to cloud environments. Because CI/CD pipelines often hold privileged access to production infrastructure, the breach poses a systemic risk to the software supply chain, potentially affecting downstream users of the compromised projects.

GitHub responded by revoking the compromised tokens, removing the malicious workflow files, and tightening verification checks for workflow additions. Security researchers who first uncovered the campaign have shared indicators of compromise with the platform and warned developers to audit recent workflow changes, especially in repositories that accept contributions from external contributors.

Experts advise developers to adopt a layered defense: enforce code‑owner reviews for workflow files, limit the scope of repository secrets, rotate credentials regularly, and enable GitHub’s secret scanning and dependabot alerts. Organizations are also urged to monitor for unusual token usage patterns and to implement runtime protection for CI/CD environments.

While the GhostAction campaign appears to have been curtailed, its methodology underscores the evolving threat landscape targeting automation tools. Continuous vigilance and stricter governance of supply‑chain assets will be essential to prevent similar incursions in the future.

Christina Kyriasoglou — Bloomberg (Berlin, Germany)

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related