BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

GhostAction compromises two top GitHub devs, hits 340 repos

GhostAction campaign compromised maintainers, stole secrets, and injected miner across hundreds of repos.

  • Two high-profile open-source maintainer accounts were compromised, pushing a malicious workflow into over 340 repositories.
  • The GhostAction campaign has stolen thousands of secrets, including AI API keys, cloud credentials, and GitHub tokens.
  • Attackers also injected an XMRig cryptocurrency miner into a Docker image in one repository, though no malicious packages have been published yet.

Cybersecurity researchers have disclosed an ongoing credential-theft campaign that compromised two prominent open-source maintainer accounts, pushing a malicious workflow into over 340 repositories. The campaign, attributed to GhostAction, first came to light in September 2025 and has now expanded significantly, according to StepSecurity.

- Advertisement -

The attacker used the account of Takashi Kitao to push a malicious workflow to 27 repositories, and eight hours later, the account of Henry Wu pushed the same workflow to 318 repositories within 16 minutes. Socket reported that over 500 GitHub accounts have committed the malicious workflow to tens of thousands of repositories since October 7, 2026.

The workflow exfiltrates sensitive data including CI/CD secrets, cloud credentials, and AI API keys to a hard-coded IP address over plain HTTP. The attack chain involves obtaining a maintainer’s GitHub credentials, scanning repository secrets, and injecting a malicious workflow under the victim’s identity, as noted in a previous StepSecurity report.

GitGuardian noted that the campaign pushed the malicious workflow to 772 public repositories between August 31 and September 30, 2026. In one case, attackers altered a repository to embed an XMRig cryptocurrency miner in the project’s Docker image.

Developers are advised to check their repositories for the malicious workflows and assume compromise if present. Affected users should revoke compromised credentials and delete the malicious workflows from all branches.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OCC fines AmEx $350M over $13B money laundering

The OCC found American Express National Bank processed approximately $13 billion in suspected trade-based...

AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw...

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

Must Read

7 Best Cryptocurrency Lending Platforms in 2025 (Ranked & Reviewed)

QUICK LINKSOur MethodologyHow to Choose the Best Crypto Lending Platform: Key Factors to ConsiderIn-Depth Reviews of the 7 Best Crypto Lending Platforms1. Nexo -...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading