Researchers have detailed an ongoing credential-theft campaign that abuses trusted open-source maintainer accounts to inject malicious GitHub Actions workflows into repositories. According to StepSecurity, the attacker used the account of pyxel author Takashi Kitao to push a malicious workflow to 27 repositories, then used Henry Wu's account—original author of Uber's athenadriver—to push the same workflow to 318 repositories in a 16-minute window. Socket says it has identified more than 500 GitHub accounts that committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

Named GhostAction, the campaign was first seen in September 2025. The injected workflows, usually named security-audit.yml or github_actions_security.yml, exfiltrate repository secrets and credentials to a hard-coded IP address over plain HTTP. The payload scans the working tree and full git history for credential patterns tied to AWS, AI services, source control, and SaaS and cloud providers. GitGuardian reported that between August 31 and September 30, 2026, the campaign pushed the workflow to 772 public repositories belonging to 373 users and organizations, targeting 2,577 secrets. In one case, attackers also embedded an XMRig cryptocurrency miner in a project's Docker image.

Researchers believe the attackers obtain maintainer credentials, likely leaked personal access tokens from infostealer logs, then inject the workflow into the default branch under the victim's identity. They advise developers to check for either workflow name since August 31, assume compromise if present, revoke the compromised GitHub credential, rotate secrets, delete the workflow from all branches, and inspect forks. Socket warns that forks are at risk, and private forks and downstream mirrors are especially exposed because private repositories are where committed credentials are most likely to be found.