GhostAction is a software supply-chain credential-theft campaign targeting public GitHub repositories and their GitHub Actions CI/CD environments. Attackers use compromised maintainer accounts and stolen GitHub access to inject malicious workflows through automated GitHub API activity. These workflows masquerade as security checks, execute when legitimate repository pushes occur, collect selected repository secrets, and transmit them to attacker-controlled infrastructure using HTTP POST requests. Targets include package-publishing tokens, cloud access keys, SSH private keys, deployment credentials, container-registry credentials, database passwords, and other API tokens.
First disclosed in September 2025, GhostAction compromised at least 817 public repositories and collected at least 3,325 secrets. A subsequent wave between August 31 and September 30, 2026, affected 772 repositories across 373 users and organizations and targeted 2,577 secrets. Confirmed successful executions in that wave enabled theft of 26 secrets from 13 repositories; many other workflow runs were held for approval. The campaign maintains persistent credential-collection opportunities through workflows that survive incomplete remediation and can execute again on later pushes. Attackers have also updated previously implanted workflows to redirect exfiltration to new infrastructure. GhostAction targets developer and open-source publishing environments rather than a particular operating system or industry; the name denotes a campaign centered on malicious CI/CD workflows, not an established standalone malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named supply-chain campaign using malicious GitHub Actions workflows rather than a standalone malware binary. Operators use stolen GitHub account access to inject workflows that reference existing repository secrets and exfiltrate them through HTTP POST requests. The latest wave targeted 2,577 secrets; researchers confirmed theft of 26 secrets from 13 repositories. Previously injected workflows provide persistence and can be updated with new exfiltration endpoints.
Named attack tooling/campaign referenced as having compromised hundreds of repositories via automated abuse of GitHub Actions workflows.
Named supply-chain incident affecting the JavaScript/npm ecosystem (no further technical details provided in the content).
Malicious GitHub Actions workflow used in a supply chain attack to exfiltrate secrets and credentials from compromised repositories and projects.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.