GhostAction Attack Compromises Hundreds of GitHub Repos to Steal CI/CD Credentials
The latest surge of the GhostAction supply‑chain intrusion has been linked to over 770 public GitHub repositories, in which rogue workflow files were employed to extract credentials from continuous‑integration and delivery pipelines.
According to an analysis released by cybersecuritynews, the campaign ran throughout September 2026—starting on August 31 and ending on September 30. investigators pinpointed 772 repositories containing forged GitHub Actions workflow definitions that execute automatically whenever a project's CI/CD pipeline is invoked.
The fake workflows take advantage of GitHub Actions’ trust framework: adding a workflow file prompts the platform to issue short‑lived tokens that give the workflow permission to read repository secrets. The malicious code captures those tokens and relays them to outside servers, allowing the perpetrators to collect 2,577 secrets in total—ranging from API keys and cloud‑service credentials to deployment tokens.
With the exfiltrated secrets, attackers can masquerade as authentic build agents, inject malicious code into downstream projects, or infiltrate cloud environments without permission. Since CI/CD pipelines frequently possess elevated rights to production systems, this compromise introduces a systemic threat to the software supply chain, potentially impacting downstream consumers of the affected repositories.
GitHub’s reaction involved revoking the hijacked tokens, deleting the malicious workflow files, and strengthening verification procedures for new workflow submissions. The security researchers who initially detected the campaign supplied GitHub with indicators of compromise and cautioned developers to review recent workflow modifications, particularly in repos that permit external contributions.
Specialists recommend a multi‑layered defense strategy: require code‑owner approval for workflow files, restrict the breadth of repository secrets, rotate credentials on a regular cadence, and activate GitHub’s secret‑scanning and Dependabot alerts. Additionally, organizations should watch for anomalous token‑usage behavior and deploy runtime safeguards for their CI/CD environments.
Although the GhostAction operation seems to have been halted, its tactics highlight the shifting threat landscape aimed at automation utilities. Ongoing vigilance and tighter governance of supply‑chain assets will be crucial to avert comparable breaches moving forward.
Comments (0)
Be the first to comment.
Join the discussion