← Back to Daily Briefing (GitHub)

GhostAction Campaign Compromises 500+ GitHub Accounts to Steal Cloud and AI API Credentials

Published October 10, 2026

The GhostAction campaign compromised over 500 GitHub maintainer accounts, injecting malicious GitHub Actions workflows into more than 340 repositories to exfiltrate cloud and AI API credentials. Attackers utilized stolen Personal Access Tokens (PATs) with repo, workflow, and admin:org scopes to deploy obfuscated shell scripts and base64-encoded payloads. These workflows exfiltrated critical secrets—including AWS, GCP, Azure, OpenAI, and Hugging Face tokens—to attacker-controlled domains: ghostaction.xyz, exfiltrate.cloud, and apistealer.net. One critical CI/CD repository alone yielded approximately 3,325 exfiltrated secrets, exposing high-value cloud resources and AI models to significant theft and unauthorized usage.

  • Incident Overview: Scope of Breach

    • Over 500 high-profile GitHub maintainer accounts were compromised.
    • Malicious workflows were injected into more than 340 distinct repositories.
    • Approximately 3,325 secrets were exfiltrated from a single critical CI/CD repository.
    • Targeted projects include popular open-source game engines, ML libraries, and DevOps tooling.
  • Attack Mechanics: Exploitation and Payload

    • Attackers leveraged stolen PATs with high-privilege repo, workflow, and admin:org scopes.
    • Malicious workflows were disguised as legitimate CI steps, such as PR triggers or scheduled jobs.
    • Obfuscated shell scripts and base64-encoded payloads were used to evade detection.
    • Exfiltration was performed via curl to C2 endpoints: ghostaction.xyz, exfiltrate.cloud, and apistealer.net.
  • Impact Analysis: Cloud and AI Exposure

    • Stolen credentials included AWS, GCP, and Azure service accounts and client secrets.
    • AI/ML infrastructure was targeted via exfiltrated OPENAI_API_KEY and HUGGINGFACE_TOKEN values.
    • Potential financial impact involves millions of dollars in unauthorized cloud resource consumption.
    • The campaign demonstrates massive supply-chain risk through trusted open-source maintainers.
  • Indicators of Compromise: Detection Artifacts

    • Malicious Domains: ghostaction.xyz, exfiltrate.cloud, apistealer.net.
    • Compromised PAT Patterns: ghp_* tokens with broad organizational and workflow scopes.
    • Anomalous Audit Logs: Unusual repository pushes from maintainer accounts at irregular UTC times.
  • Defensive Strategy: Remediation and Hardening

    • Enforce the principle of least privilege for all Personal Access Tokens (PATs).
    • Enable and monitor GitHub secret scanning and audit logs for anomalous activity.
    • Require mandatory manual approval for all new or modified GitHub Actions workflows.
    • Implement strict branch protection rules to prevent unauthorized code and workflow pushes.

Related posts

  1. gbhackers.com — GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials
  2. Devops
  3. thehackernews.com — Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
  4. Mallory
  5. Reddit
  6. Threats
  7. Hackread
  8. Bleepingcomputer
  9. Daily
  10. Cybersecuritynews
  11. Rescana

LINK COPIED TO CLIPBOARD