- What: Attackers using stolen maintainer credentials pushed a fake security audit GitHub Actions workflow into tens of thousands of repositories, including 345 from two high-profile maintainer accounts.
- Impact: The workflow exfiltrates named Actions secrets plus AWS, AI provider, GitHub and GitLab credentials found in the working tree and the entire git history to 193.32.204[.]199 over plain HTTP.
- Fix / mitigation: There is no patch because no software flaw is involved: StepSecurity, Socket and GitGuardian advise treating any repository containing security-audit.yml or github_actions_security.yml since August 31, 2026 as compromised, with credential revocation, rotation and workflow removal across all branches and forks.
- Who's at risk: Any organization that owns, forks, mirrors or synchronizes with an affected repository, with private forks and downstream mirrors the most exposed.
An ongoing credential-theft campaign has planted a malicious GitHub Actions workflow in tens of thousands of repositories. Socket reports that as of October 9, 2026 it had identified more than 500 GitHub accounts that committed the workflow since October 7. The workflow poses as a security audit, lands on the default branch under the victim's own identity, and sends harvested secrets to a hard-coded IP address over plain HTTP.
The activity is attributed to GhostAction, a supply chain campaign that first came to light in September 2025. That earlier wave hit 817 repositories across 327 GitHub users and exfiltrated 3,325 secrets, including PyPI, npm and DockerHub tokens. The current wave is larger by more than an order of magnitude in repository count.
Two maintainer accounts, 345 repositories
StepSecurity documented two high-profile account compromises inside the wider campaign. The first belonged to Takashi Kitao, author of the 18,400-star game engine pyxel. The attacker used that account to push the malicious workflow to 27 repositories starting at 13:20 UTC.
Eight hours later the account of Henry Wu (henrywoo), the original author of Uber's athenadriver, was used to push the same workflow to 318 repositories in a 16-minute window, from 21:10 to 21:26 UTC. That works out to about 20 repositories per minute, a pace that points to scripted injection.
Because the commits come from the legitimate maintainer account, they carry the maintainer's identity. Nothing in the commit metadata separates them from routine housekeeping, and the file names are chosen to look like a hardening measure.
How the workflow steals credentials
The researchers describe a four-stage chain:
- The attacker obtains a maintainer's GitHub credentials, most likely a leaked personal access token (PAT) from infostealer logs or credential dumps.
- The repository's existing workflow files are scanned to learn which named secrets it uses.
- A workflow named Security Audit (security-audit.yml) or GitHub Actions Security (github_actions_security.yml) is injected into the default branch.
- The embedded payload collects the data and sends it to an attacker-controlled endpoint with curl.
According to StepSecurity, the workflow triggers on workflow_dispatch and on an unfiltered push, meaning any branch and any tag. It checks out the repository with fetch-depth: 0, which pulls the complete commit history, then runs a single step named Audit that does four things:
- Appends the repository's named Actions secrets identified during reconnaissance.
- Scans the working tree for 13 credential patterns covering AWS keys, AI services, source control services, and SaaS and cloud API keys.
- Scans the entire git history for the same 13 patterns, recovering credentials that were committed by mistake and later deleted.
- Pairs AWS access key IDs with their matching secret access keys.
The captured data includes CI/CD secrets, AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens. The history scan is the detail that matters most: deleting a leaked key from the current tree does not remove it from the history, and this workflow reads all of it.
Workflow files named security-audit.yml (Security Audit) or github_actions_security.yml (GitHub Actions Security), added on or after August 31, 2026. Outbound plain HTTP traffic from CI runners to 193.32.204[.]199. Researchers say the presence of either file should be treated as a compromise.
A campaign that has been running for weeks
The October spike is not the start. GitGuardian reported earlier in the week that GhostAction pushed the malicious workflow to 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026. Those injected workflows targeted 2,577 secrets.
The targeted secret types in that period were broad: SSH private keys, Azure credentials, DockerHub and GHCR container registry credentials, database credentials, AWS access keys, FTP credentials, Google Cloud and Firebase credentials, GitHub tokens, Telegram, Slack and Discord bot tokens, and keys for Cloudflare, npm, PyPI and AI providers.
In at least one case, observed on August 30, 2026, the threat actors went beyond theft and altered the kuafuai/DevOpsGPT repository to embed an XMRig cryptocurrency miner in the project's Docker image. As of the reporting, no malicious package releases had been published using compromised publishing credentials. That is a statement about what has been observed so far, not a guarantee about stolen npm, PyPI or registry tokens that remain valid.
Forks and private mirrors extend the blast radius
Cleaning the upstream repository does not end the exposure. Socket noted that the 279 forks in the henrywoo namespace each carry the workflow file, and that if Actions are enabled, subsequent pushes can trigger credential harvesting. Downstream forks are also at risk when they inherit the workflow, either at creation or by synchronizing with an affected upstream.
Socket singled out private forks and downstream mirrors as the most exposed, because private repositories are where committed credentials are actually found. An internal mirror of a public project, synced automatically, can pull the workflow into an environment with far more valuable secrets than the public original ever held.
Socket reports that every run returns a repository identifier whether or not credentials were found. The operator therefore holds a list of repositories where their code executes, independent of any credential theft.
What the researchers advise
There is no vendor patch for this campaign because it does not exploit a software vulnerability. It abuses valid credentials and the normal behavior of GitHub Actions. The guidance from the researchers is to check repositories for either of the two workflow files added since August 31, 2026, and to assume compromise if one is present. Their recommended response covers revoking the compromised GitHub credential, rotating exposed credentials, deleting the malicious workflow from all branches, and checking forks of infected repositories.
The scope of rotation is the hard part. Because the payload reads the full git history, the affected set includes every credential that ever appeared in a commit, not only those currently in use.
RedEye assessment
Three points stand out. First, the entry point is most likely a single leaked PAT per maintainer, and the source reporting labels that as probable, not confirmed. A long-lived token with broad repository scope turned one infostealer infection into 318 poisoned repositories in 16 minutes.
Second, the campaign is growing. It went from 817 repositories in September 2025, to 772 across one month in 2026, to tens of thousands in roughly three days. The tooling is automated and the supply of stolen developer tokens is not shrinking.
Third, the theft and the use of stolen credentials are separate events. No malicious package releases have been reported yet, but publishing tokens, cloud keys and AI provider keys taken in this wave stay usable until they are rotated. Organizations that depend on open-source projects, or that mirror them internally, should treat this as an active exposure with a follow-on phase that has not been observed yet.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us