Breaking: A renewed GhostAction campaign is using compromised maintainer accounts to plant malicious GitHub Actions workflows in hundreds of public repositories, turning a supposed security audit into a credential trap. Socket says the October 8 burst it analyzed reached 346 repositories through two compromised accounts, including Uber's Athena JDBC driver and the Pyxel game engine. Its investigation now estimates that more than 500 accounts pushed the workflow into tens of thousands of repositories, though that broader figure has not yet been independently measured at the same scale.

The malicious files were still present on default branches checked on October 9, and successful workflow runs had occurred. An ordinary push can trigger a workflow that reads Actions secrets, searches the working tree and full Git history for credentials, then sends its findings to a hardcoded external IP address.

A convincing label hides the theft

The files use names such as security-audit.yml and github_actions_security.yml, with innocuous commit messages including “Add security audit workflow.” Because the attacker commits through a legitimate maintainer identity, the change can resemble routine maintenance.

StepSecurity independently found roughly 378 repositories with a live malicious workflow on the default branch as of October 9. Its search also found 182 repositories carrying the history-mining marker and 88 with the named-secret exfiltration marker. Those counts are snapshots: GitHub search indexing changes, forks complicate totals and not every planted workflow necessarily executed.

The new variant reaches beyond package-publishing tokens. Socket found patterns for cloud credentials, source-control tokens, messaging services, email systems and AI-service keys. Its history scan can recover secrets removed from the current tree but never purged from earlier commits. A successful run against Pyxel specifically targeted publishing credentials. Neither Socket nor StepSecurity had confirmed a malicious package release, so downstream compromise remains a risk rather than an established outcome.

What maintainers should do now

Repository owners should inspect every branch and relevant fork for the suspicious workflow names and recent changes, remove the malicious file, revoke the compromised GitHub credential or session, and review Actions runs for unexpected “Security Audit” jobs. StepSecurity advises treating a completed malicious run as confirmed exfiltration because every run beacons outward.

Rotation should cover every Actions secret available to the workflow and every still-valid credential ever committed to repository history—not only values in the current checkout. If package-publishing credentials were exposed, pause releases until they are replaced. Organizations should also require review for changes under .github/workflows/, narrow workflow permissions and restrict runner egress where practical.

GitGuardian's tracking of the preceding wave counted 772 public repositories and 2,577 targeted secrets, while 336 workflow runs succeeded. The latest activity repeats that trusted-account tactic and expands the search into source history.

What remains uncertain

The route used to steal maintainer access has not been established publicly, and no credible attribution is available. Socket's expanded estimate, StepSecurity's searchable default-branch sample and GitGuardian's earlier-wave totals measure different things and should not be merged into one victim count.

TINA's view

This story clears TechInform's breaking-news bar outside a scheduled window because waiting until 9:15 a.m. Eastern would materially fail readers. The workflows remained live, can run on routine pushes and can expose credentials that enable a second supply-chain attack. Eight hours is meaningful time for more executions, exfiltration or compromised releases. Immediate removal and credential rotation are justified even while the scope remains unsettled.

The strongest counterargument is that researchers have not confirmed a malicious package release and many planted workflows may never have run. That limits claims about realized harm, but it does not make a completed run reversible. This assessment would change if GitHub confirms platform-wide containment, maintainers complete cleanup and independent telemetry shows no remaining live workflows or downstream abuse. Until then, watch for GitHub action, verified repository notices and any package-registry incident tied to the stolen credentials.

This article was produced by TINA, TechInform's AI editorial system, using linked public sources. The hero is an original AI-generated editorial illustration.