Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GhostAction Breach Exposes GitHub Repositories to Secret Theft

GhostAction Breach Exposes GitHub Repositories to Secret Theft

Posted on October 9, 2026 By CWS

A recent GhostAction campaign has infiltrated hundreds of GitHub repositories, exploiting two compromised maintainer accounts to introduce a deceptive “security audit” workflow. This tactic, aimed at extracting CI/CD secrets, cloud keys, and credentials from source-code history, has affected 346 repositories.

Details of the GhostAction Campaign

Security firm Socket identified that the breach occurred on October 8, involving repositories associated with the GitHub accounts ‘henrywoo’ and ‘kitao.’ Notably, targets included Uber’s ‘uber/athenadriver’ and the widely used ‘kitao/pyxel’ project, which boasts over 18,000 stars on GitHub.

The fraudulent file, ‘.github/workflows/security-audit.yml,’ was introduced via commits labeled “Add security audit workflow” and “Update security audit workflow.” These changes highlight how a compromised GitHub maintainer account can jeopardize more than just a single repository.

Impact on Continuous Integration and Delivery

Once attackers obtained write access, the malicious workflow was added to each accessible repository, activating automatically when developers pushed code. This action placed sensitive CI/CD credentials within reach of the attacker. According to Socket’s investigation, the workflow transmitted stolen data via HTTP POST requests to 193.32.204[.]199.

The compromised workflow harvested secrets from GitHub Actions workflows, including PyPI passwords, GitHub tokens, and other credentials. Additionally, the GhostAction version scanned repository files and the complete Git history, searching for hardcoded secrets, a significant enhancement from previous iterations.

Preventive and Remedial Measures

Security researchers observed that the attack appeared highly automated, impacting 318 repositories under the ‘henrywoo’ namespace and 27 under ‘kitao,’ including many inactive for years. This suggests the use of automated tools for repository discovery.

In response, affected teams are advised to revoke GitHub sessions, personal access tokens, and all secrets mentioned in the workflow. They should review Git history, scrutinize GitHub Actions run records, and monitor network logs for suspicious activity. Implementing strict branch rules and least-privilege permissions can mitigate future risks.

As of October 9, no malicious packages have been published to platforms like PyPI or crates.io, but vigilance remains crucial. GitHub secret scanning and push protection can further safeguard against similar threats.

This breach emphasizes the ongoing vulnerability of CI/CD environments to supply-chain attacks, underscoring the importance of robust security measures for open-source projects.

Cyber Security News Tags:API tokens, CI/CD vulnerabilities, cloud keys, Cybersecurity, GhostAction, GitHub, open source security, repository security, secret theft, supply chain attack

Post navigation

Previous Post: P7 DarkSword iOS Exploit Kit Targets Crypto Wallets
Next Post: Anthropic Introduces AI Tool for Open-Source Security

Related Posts

Attackers are Using WSL2 as a Stealthy Hideout Inside Windows Systems Attackers are Using WSL2 as a Stealthy Hideout Inside Windows Systems Cyber Security News
Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments Threat Actors Leverage Oracle Database Scheduler to Gain Access to Corporate Environments Cyber Security News
MacSync Malware Targets macOS for Crypto and Data Theft MacSync Malware Targets macOS for Crypto and Data Theft Cyber Security News
Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Security News
Blockchain for Cybersecurity Real-World Applications and Limits Blockchain for Cybersecurity Real-World Applications and Limits Cyber Security News
Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode Windows 11 24H2/25H2 Update Blocks Mouse and Keyboard in Recovery Mode Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests
  • Anthropic Introduces AI Tool for Open-Source Security
  • GhostAction Breach Exposes GitHub Repositories to Secret Theft
  • P7 DarkSword iOS Exploit Kit Targets Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests
  • Anthropic Introduces AI Tool for Open-Source Security
  • GhostAction Breach Exposes GitHub Repositories to Secret Theft
  • P7 DarkSword iOS Exploit Kit Targets Crypto Wallets

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark