Skip to content

Image: cdn.sanity.io · rights & removal

Executive Summary

A GhostAction campaign has expanded beyond stealing secrets from GitHub Actions to sweep for cloud and AI service credentials committed into source code and Git history. The activity involved two compromised maintainer accounts, henrywoo and kitao, who committed a malicious workflow file named security-audit.yml across hundreds of repositories. This workflow executes a multi-stage process: first, it collects existing GitHub Actions secrets; second, it sweeps the working tree and full git history for specific credential patterns; and finally, it posts collected data to an external IP address. The additional sweep targets AWS access keys and AI service API keys by analyzing both current files and the complete commit history, suggesting a shift toward accessing deeper, historical context within the repository structure rather than just runtime secrets.

Facts Only

* Two GitHub accounts, henrywoo and kitao, pushed commits on October 8, 2026.
* The workflow file security-audit.yml was committed to 346 repositories.
* The execution involved collecting GitHub Actions secrets from existing workflows.
* A new component swept the working tree and full git history for credentials.
* The sweep collected data from `git log -p --all` and file content, targeting 13 specific credential patterns.
* Specific targets included AWS access key IDs (AKIA/ASIA), Anthropic, OpenAI, and GitHub tokens.
* Injected workflows successfully ran in affected repositories.
* The payload exfiltrated data via a POST request to hxxp://193.32.204[.]199.
* The most exposed repository identified is kitao/pyxel, which contains publishing credentials for PyPI and crates.io.

Full Take

The shift from targeting ephemeral GitHub Actions secrets to committing credential harvesting logic directly into the repository history represents a significant escalation in threat sophistication. The campaign evolved from exploiting runtime environments (Actions secrets) to leveraging the persistence of Git history, specifically the full patch text retrieved via `git log -p --all`, to discover static credentials like long-term AWS keys and AI service tokens that developers believed were secured by scope or lifecycle management. This pattern suggests an attacker is moving beyond simple compromise to establishing persistent, deep reconnaissance within the codebase itself, understanding that historical context often contains more valuable, long-lived secrets than current environment variables. The collection method focuses heavily on contextualizing credential identifiers (like AWS key IDs) by looking at surrounding lines in both the working directory and the historical log, implying an effort to reconstruct complete, usable key sets rather than just stealing surface-level tokens. The focus on repositories with large followings, like kitao/pyxel, signals a clear pivot toward supply chain exploitation where artifact publishing credentials are the ultimate goal. The implicit cost is that developers must now treat their entire Git history, including potentially stale or deleted commits, as an exposure surface for highly sensitive cloud and AI access keys.

From the original · Socket Security Blog

A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history. - Socket Research Team Update (October 9, 2026, [HH:MM] UTC): Since publication, Socket has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026, including several…
Read the full story at socket.dev

Sentinel — Human

Confidence

LIKELY_HUMAN (confidence: 0.2)

New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials | Huntaegis