preloader

· · devops github supply-chain cicd secrets digital-security europe

GhostAction Is Back: 772 GitHub Repositories Targeted in a New CI/CD Secret Stealing Wave

Source: GitGuardian

The supply chain campaign that GitGuardian first exposed in September 2025 under the name GhostAction never really went away. In new research published this week, the company documents a fresh wave that started on August 31, 2026 and ran through the end of September, pushing a malicious workflow into 772 public GitHub repositories owned by 373 different users and organizations. The injected workflows target 2,577 secrets in total, from SSH private keys and deployment credentials to Azure, AWS, Google Cloud, Docker Hub and GitHub tokens.

How the attack works

The technique is identical to the 2025 wave. A workflow file named github_actions_security.yml is committed to the victim repository with the message “Add Github Actions Security workflow”. Instead of dumping the whole environment, the workflow hardcodes the names of secrets referenced in the repository’s legitimate workflows and sends their values in a single HTTP POST request to an attacker controlled server, in this wave a bare IP address. Every commit is made with the victim’s own identity, almost certainly using previously stolen credentials, which is how the campaign sustains itself. A September 7 variant even posts each injection with a unique identifier, suggesting the attackers now track which stolen secret came from which repository.

The cleanup problem is the real story

Of the 3,669 workflow runs GitGuardian collected across 605 repositories, only 499 executed, in 32 repositories, and 336 completed successfully, exfiltrating 26 secrets from 13 repositories. The more alarming number is the cleanup rate: by October 5, only 124 of the 772 affected repositories, about 16 percent, had been effectively cleaned in public commit history. Because the malicious workflow triggers on every push, a repository that merely deleted the workflow in the latest commit but not from its history can run it again the next time a developer pushes. Dozens of later commits across victim repositories explicitly describe removing a credential exfiltrating workflow, which tells you the victims often discovered the injection late.

What European engineering teams should do

The most targeted secret categories were SSH private keys and deployment credentials, followed by Azure credentials, container registry credentials, database credentials and AWS keys. If your organization hosts code on GitHub, search your repositories and their history for unexpected workflow files, especially anything named github_actions_security.yml or security-check.yml, review the Actions run logs for outbound POST requests to unknown endpoints, and treat any secret that existed in an affected repository as burned and rotate it. Requiring approval for workflow runs from new contributors and pinning third party actions closes the two doors this campaign walked through.

If you want an independent review of your CI/CD posture, including workflow history analysis and secrets hygiene across your GitHub estate, contact Excello Digital at https://excello.digital/contact/. We help European teams find exposed credentials before attackers do and put guardrails in place that stop injected workflows from ever running.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!