GhostAction Malware Targets GitHub Actions to Steal Secrets

GhostAction Malware Targets GitHub Actions to Steal Secrets

A persistent threat actor has been reusing dormant infections from 2025 by simply updating the exfiltration endpoints to a new bare IP address. This specific operation, identified as the GhostAction campaign, highlights the extreme vulnerability inherent in modern CI/CD pipelines where automation and speed often outpace traditional security auditing. By the summer of 2026, the campaign had expanded its reach to compromise nearly 800 public repositories across hundreds of distinct organizations, demonstrating a high level of persistence and technical adaptability. These attacks are not isolated incidents but represent an ongoing effort to exploit the trusted relationship between developers and their automated build environments. By injecting malicious workflows directly into the heartbeat of the development process, the actors are able to harvest sensitive secrets that provide long-term access to a company’s cloud infrastructure and private data services.

The Mechanics of Surgical Secret Theft

The operational success of the GhostAction campaign is deeply rooted in its ability to mimic legitimate developer activities within a repository. Unlike noisier malware that attempts to exfiltrate massive amounts of data indiscriminately, GhostAction operates with a level of surgical precision that allows it to remain undetected for extended periods. The attackers do not merely guess which secrets might be present; they perform a detailed analysis of the target environment to ensure their efforts are as efficient as possible. This approach minimizes the risk of triggering automated security alerts that typically fire when unusual environment-wide data dumps are detected. By understanding the specific naming conventions used in a project’s legitimate workflow files, the malware can tailor its exfiltration scripts to target only the most sensitive credentials. This methodical preparation ensures that when the malicious code runs, it delivers high-value assets directly to the attacker.

Strategic Injection and Exfiltration

The core mechanism of the attack begins with identifying a vulnerable repository and gaining write access, often achieved through previously leaked personal access tokens or compromised developer accounts. Once inside the repository, the attacker introduces a malicious workflow file that is given a professional and unassuming name to blend in with standard security tools. By using commit messages that mention adding security checks or enhancing workflow protection, the threat actor exploits the natural tendency of developers to trust security-related updates. This social engineering aspect is a critical component of the campaign, as it reduces the likelihood of manual code reviews questioning the new file’s presence. Once the workflow is committed, it is configured to trigger on common events like a code push, ensuring that the malicious logic is executed frequently and reliably during the development cycle without requiring further manual intervention from the operator.

Within the malicious workflow itself, the attacker utilizes a highly customized script that is specifically designed to target the secrets identified during the initial scraping phase. Instead of running generic commands, the workflow contains hardcoded references to specific environment variables such as AWS access keys, SSH private keys, or deployment server credentials. When the GitHub Actions environment initializes, the workflow executes a simple but effective command to send these secret values to an external server. This is typically done using a standard POST request, which is a common activity in many legitimate workflows that integrate with third-party services. Because the exfiltration looks like a standard API call, it often bypasses network-level monitoring that might be looking for more unusual outbound traffic patterns. This surgical approach ensures the theft of high-value data and provides the attacker with a repeatable framework for their future use.

Infrastructure Shifts and Data Management

The 2026 iteration of the GhostAction campaign saw a significant shift in the underlying infrastructure used for data exfiltration and command-and-control operations. In previous versions of the attack, the threat actors relied on registered domain names and subdomains that were often hosted on popular web management platforms. However, as security vendors began to block these known malicious domains, the attackers adapted by moving toward the use of bare IP addresses for their data collection endpoints. This move to direct IP communication makes it more difficult for traditional domain-based reputation services to block the traffic, as the endpoints can be easily rotated without the overhead of registering new domains. In the latest surge, a specific IP address, 193.32.204.199, became a central hub for receiving stolen secrets from a wide range of compromised repositories. This shift demonstrates the attacker’s commitment to maintaining a resilient infrastructure for their data.

Beyond the change in network addressing, the attackers also improved their backend data management capabilities by implementing more structured API endpoints for receiving exfiltrated data. Researchers observed the use of specialized URL parameters that allowed the attacker to categorize incoming secrets by specific injection identifiers, essentially creating a database of stolen assets that could be sorted by target and secret type. This level of organization indicates that the campaign is being run by a professional entity that views these credentials as a strategic resource to be managed and exploited over time. The use of unique IDs for each injection also suggests that the attackers are tracking the success rate of different injection methods to further refine their tactics. This data-driven approach to cybercrime allows them to scale their operations efficiently, moving from a few dozen compromises to hundreds within a very short timeframe during the peak of the campaign.

Scale and Historical Persistence of the Campaign

The volume of the GhostAction campaign in 2026 provides a stark look at the massive scale of modern automated supply chain attacks. This was not a gradual increase in activity but rather a series of highly aggressive, concentrated bursts that targeted hundreds of repositories in rapid succession. During these periods of high activity, the attackers were able to attempt the theft of thousands of individual secrets, representing a massive potential for downstream compromise. The diversity of the targeted credentials is particularly concerning, as it includes everything from cloud infrastructure keys and database passwords to private communication tokens for platforms like Slack and Discord. This breadth of targeting suggests that the attackers are not just looking for a single type of access but are trying to gain as much visibility and control over a victim’s technical ecosystem as possible. The impact of such a broad campaign is felt across the industry as stolen credentials fuel further attacks.

Aggressive Bursts of Activity

The timeline of the 2026 resurgence shows a pattern of activity that is designed to overwhelm security teams and take advantage of periods where oversight might be less intense. The campaign began with a significant spike in late August, where over a hundred repositories were compromised in a single day, followed by an even larger wave in early September that saw nearly three hundred more repositories targeted. These bursts of activity often align with weekends or holidays, further increasing the chance that the malicious commits will go unnoticed for a longer period of time. The efficiency with which the attackers move from one repository to the next suggests a high degree of automation in their scanning and injection tools. By the time a security researcher or repository owner identifies a single malicious workflow, the attacker has already moved on to dozens of other targets, leaving a trail of compromised secrets in their wake as they move across the software landscape.

The success of these bursts is also tied to the way GitHub Actions handles workflow execution for public repositories, where certain events can trigger workflows even if they have not been explicitly approved by a maintainer. Although GitHub has implemented several security controls to mitigate the impact of unauthorized workflows, the GhostAction campaign found ways to exploit the typical development cycle. Because the malicious files are often triggered by subsequent legitimate commits made by the actual repository owners, they can bypass some of the protections designed to stop external contributors from running arbitrary code. In total, several hundred workflow runs were successfully completed, leading to the confirmed exfiltration of sensitive secrets from multiple organizations. While the overall success rate for each individual run might seem low, the cumulative effect of stealing high-value secrets across a diverse range of targets provides the attacker with leverage.

The Myth of Dormancy

One of the most revealing aspects of the 2026 investigation into GhostAction is the discovery that many of the new infections were actually updates to malicious code that had been planted years earlier. This reality challenges the common perception that supply chain attacks are transient events that end once a specific wave of activity has been identified and mitigated. Instead, the threat actor treated their presence in these repositories as a long-term asset, returning to dormant infections to refresh the infrastructure used for exfiltration. By simply updating the URL or IP address in an existing malicious workflow, the attacker was able to re-establish a connection to their command-and-control server without having to perform a new injection. This level of persistence is dangerous because it means that a repository compromised in 2025 could still be actively leaking secrets in 2026 if the original malicious file was never properly identified and removed by the project owners.

The longevity of the campaign is further evidenced by the consistent use of certain tactics and techniques that have remained largely unchanged over several years of activity. While the specific servers and IP addresses used for data collection have rotated, the core logic of the GhostAction malware has remained remarkably stable. This suggests that the threat actor has found a highly effective formula that continues to deliver results despite the ongoing efforts of the security community to stop them. The persistence of the campaign also points to a dedicated operator who is willing to maintain a baseline of activity even during periods when there is no major surge in new compromises. This constant pressure on the software supply chain means that developers must remain vigilant at all times, rather than only focusing on security during major alerts. The realization that an infection can remain dormant and then be reactivated highlights the importance of a trust but verify approach.

Comprehensive Remediation Strategies: The Road to Recovery

The widespread resurgence of the GhostAction campaign in 2026 underscored the fundamental reality that securing a modern software supply chain required far more than just surface-level cleanup. Organizations that attempted to remediate the threat by simply deleting the malicious workflow files soon discovered that their environments remained vulnerable because the original entry points were left unaddressed. It became clear that the presence of the malware was merely a symptom of a deeper compromise involving developer credentials or access tokens that had been leaked or stolen. As a result, the most effective defense strategies evolved to include a comprehensive audit of all access logs to pinpoint exactly how the attackers gained write access to the repository in the first place. This historical analysis allowed security teams to revoke the specific tokens or account permissions that were being exploited, finally cutting off the attacker’s ability to return for future use.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later