<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr" -->

---
title: GhostAction supply chain campaign returns, hitting...
description: GhostAction, a GitHub Actions supply chain attack first identified in September 2025, has resurfaced with a wave starting August 31, 2026 that hit 772...
canonical: https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GhostAction supply chain campaign returns, hitting hundreds of GitHub repositories | daily.dev
og:description: GhostAction, a GitHub Actions supply chain attack first identified in September 2025, has resurfaced with a wave starting August 31, 2026 that hit 772...
og:url: https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr
og:image: https://api.daily.dev/og/posts/eWpS6JEGr.png
og:image:alt: GhostAction supply chain campaign returns, hitting hundreds of GitHub repositories
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GhostAction supply chain campaign returns, hitting hundreds of GitHub repositories

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 1 comments

## Summary

GhostAction, a GitHub Actions supply chain attack first identified in September 2025, has resurfaced with a wave starting August 31, 2026 that hit 772 repositories across 373 users, targeting 2,577 secrets including SSH keys, Azure credentials, container registry tokens, database credentials and AWS keys. A separate count found 346 repos with a malicious security-audit.yml workflow, including uber/athenadriver and kitao/pyxel. The updated workflow now scans the full git history and working tree for cloud and AI credentials and exfiltrates them in cleartext to a hardcoded IP. GitGuardian's analysis suggests the campaign never actually paused between waves, just kept reusing and updating injected workflows. A separate, likely unrelated cryptominer was also found hidden in DevOpsGPT. Maintainers are urged to revoke compromised GitHub credentials (not just rotate secrets) and audit git history for old committed credentials.

## Content

GhostAction, the GitHub supply chain campaign first exposed in September 2025, is back with a new wave. It never really went away.

## What the new wave did

Attackers injected a malicious workflow file named security-audit.yml into 346 repositories, according to Socket. Uber's athenadriver and kitao/pyxel (Pyxel, 18,420 stars) were among them. Socket later said it had identified more than 500 GitHub accounts that committed the malicious workflow to tens of repositories.

GitGuardian counts differently. It puts the wave, which began August 31, 2026, at 772 repositories across 373 GitHub users, with 2,577 secrets targeted. Those include SSH keys, Azure credentials, container registry tokens, database credentials and AWS keys.

## A wider net

Earlier GhostAction workflows went after CI/CD secrets. The new one goes further. It scans the working tree and the full git history for cloud and AI credentials, then sends them in cleartext to a single hardcoded IP address.

The older approach, per GitGuardian, harvested secret names from existing workflows and exfiltrated the values with curl POST requests to attacker-controlled servers.

## Not really a comeback

GitGuardian's analysis suggests the campaign never stopped between waves. Since September 2025, the attackers have kept reusing and updating previously injected workflows across multiple exfiltration endpoints. The "new wave" is more a surge in something that was already running.

## A separate problem in DevOpsGPT

GitGuardian also found a cryptominer hidden in the popular open-source project DevOpsGPT. It was pushed through a compromised account shortly before a GhostAction injection. The evidence points to different operators, so this looks like a coincidence of targets rather than the same campaign.

## What to do if you're affected

Rotating the stolen secrets isn't enough. GitGuardian stresses that the compromised GitHub credentials behind the injections must be revoked too, since they may be shared or resold among multiple threat actors. If you only rotate the secrets, the door the attackers used is still open.

It's worth checking your repositories for a security-audit.yml you didn't write, and looking through your git history for credentials that were committed long ago and forgotten. This wave is designed to find exactly those.

## Questions this post answers

### What is the GhostAction GitHub Actions supply chain attack and how does it work?

GhostAction is a campaign where attackers use stolen GitHub credentials to push a malicious workflow, often named security-audit.yml, into repositories. The workflow reads secrets referenced in other workflows and exfiltrates them via HTTP requests to attacker-controlled servers. First exposed in September 2025, a new wave starting August 31, 2026 hit 772 repositories, 373 users, and 2,577 secrets.

_Teams hardening CI/CD pipelines against credential theft can follow supply chain security coverage on daily.dev._

### Is rotating secrets enough after a GhostAction GitHub Actions compromise?

No, rotating stolen secrets alone is insufficient because the GitHub credentials that let attackers inject the malicious workflow in the first place must also be revoked. These credentials may be shared or resold among multiple threat actors, so a rotated secret can be stolen again if the original access point remains open. Maintainers should also check git history, since the attack now reads committed history, not just the current tree.

_Maintainers responding to credential leaks can track incident response guidance like this on daily.dev._

### What data does the updated GhostAction malicious workflow steal from GitHub repositories?

The updated workflow scans both the working tree and the full git history for cloud and AI credentials, including SSH keys, Azure credentials, container registry tokens, database credentials, and AWS keys, then sends them in cleartext to a single hardcoded IP address. This goes beyond the original version, which only targeted CI/CD secrets already referenced in a repository's workflows.

_Developers auditing repositories for injected workflows can follow supply chain security news on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@etal** · 0 upvotes

> A credentials infrastructure like AgentSecrets could be useful in cases like this

## Similar posts on daily.dev

- [GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories](https://daily.dev/posts/ghostaction-returns-malicious-security-audit-workflows-now-mine-credentials-from-entire-git-histo-9iwzmwu4v) · StepSecurity · 0 upvotes · 0 comments
- [Four Credential-Harvesting Campaigns Hit Open Source Ecosystems in Two Weeks](https://daily.dev/posts/four-credential-harvesting-campaigns-hit-open-source-ecosystems-in-two-weeks-gtsbqgosw) · GitGuardian · 1 upvotes · 0 comments
- [Securing the open source supply chain across GitHub](https://daily.dev/posts/securing-the-open-source-supply-chain-across-github-k6lf4rzyu) · GitHub Blog · 0 upvotes · 0 comments
- [GitHub’s public APIs are becoming an enterprise reconnaissance tool](https://daily.dev/posts/github-s-public-apis-are-becoming-an-enterprise-reconnaissance-tool-ty1kvhyvy) · InfoWorld · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#open-source](https://daily.dev/tags/open-source), [#cicd](https://daily.dev/tags/cicd), [#github-actions](https://daily.dev/tags/github-actions), [#secrets-management](https://daily.dev/tags/secrets-management)

[View this post on daily.dev](https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GhostAction supply chain campaign returns, hitting hundreds of GitHub repositories","url":"https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr"},"datePublished":"2026-10-09T13:53:02.195Z","dateModified":"2026-10-09T21:12:59.382Z","description":"GhostAction, a GitHub Actions supply chain attack first identified in September 2025, has resurfaced with a wave starting August 31, 2026 that hit 772...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9f9629490d6dfd57db0743952e33dfe2?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/9f9629490d6dfd57db0743952e33dfe2?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"cyber,open-source,cicd,github-actions,secrets-management","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"GhostAction supply chain campaign returns, hitting hundreds of GitHub repositories"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr","comment":[{"@type":"Comment","text":"A credentials infrastructure like AgentSecrets could be useful in cases like this","datePublished":"2026-10-09T20:43:40.568Z","url":"https://daily.dev/posts/eWpS6JEGr#c-58DMobZX9","author":{"@type":"Person","name":"Wisdom Ademiju","url":"https://daily.dev/etal","image":"https://media.daily.dev/image/upload/s--iSWfWEVP--/f_auto/v1791476397/avatars/avatar_8CWhNDmJaO7smzKuYZEre?_a=BAMAMicg0"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/ghostaction-supply-chain-campaign-returns-hitting-hundreds-of-github-repositories-ewps6jegr#faq","mainEntity":[{"@type":"Question","name":"What is the GhostAction GitHub Actions supply chain attack and how does it work?","acceptedAnswer":{"@type":"Answer","text":"GhostAction is a campaign where attackers use stolen GitHub credentials to push a malicious workflow, often named security-audit.yml, into repositories. The workflow reads secrets referenced in other workflows and exfiltrates them via HTTP requests to attacker-controlled servers. First exposed in September 2025, a new wave starting August 31, 2026 hit 772 repositories, 373 users, and 2,577 secrets. Teams hardening CI/CD pipelines against credential theft can follow supply chain security coverage on daily.dev."}},{"@type":"Question","name":"Is rotating secrets enough after a GhostAction GitHub Actions compromise?","acceptedAnswer":{"@type":"Answer","text":"No, rotating stolen secrets alone is insufficient because the GitHub credentials that let attackers inject the malicious workflow in the first place must also be revoked. These credentials may be shared or resold among multiple threat actors, so a rotated secret can be stolen again if the original access point remains open. Maintainers should also check git history, since the attack now reads committed history, not just the current tree. Maintainers responding to credential leaks can track incident response guidance like this on daily.dev."}},{"@type":"Question","name":"What data does the updated GhostAction malicious workflow steal from GitHub repositories?","acceptedAnswer":{"@type":"Answer","text":"The updated workflow scans both the working tree and the full git history for cloud and AI credentials, including SSH keys, Azure credentials, container registry tokens, database credentials, and AWS keys, then sends them in cleartext to a single hardcoded IP address. This goes beyond the original version, which only targeted CI/CD secrets already referenced in a repository's workflows. Developers auditing repositories for injected workflows can follow supply chain security news on daily.dev."}}]}
```

