Image: cdn.sanity.io · rights & removal
New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials
Reporting by Socket Security BlogRead the original at socket.dev
Executive Summary
Facts Only
* Two GitHub accounts, henrywoo and kitao, pushed commits on October 8, 2026.
* The workflow file security-audit.yml was committed to 346 repositories.
* The execution involved collecting GitHub Actions secrets from existing workflows.
* A new component swept the working tree and full git history for credentials.
* The sweep collected data from `git log -p --all` and file content, targeting 13 specific credential patterns.
* Specific targets included AWS access key IDs (AKIA/ASIA), Anthropic, OpenAI, and GitHub tokens.
* Injected workflows successfully ran in affected repositories.
* The payload exfiltrated data via a POST request to hxxp://193.32.204[.]199.
* The most exposed repository identified is kitao/pyxel, which contains publishing credentials for PyPI and crates.io.
Full Take
From the original · Socket Security Blog
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history. - Socket Research Team Update (October 9, 2026, [HH:MM] UTC): Since publication, Socket has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026, including several…Read the full story at socket.dev
Sentinel — Human
LIKELY_HUMAN (confidence: 0.2)
