GhostAction is a software supply-chain intrusion campaign centered on the compromise of GitHub repositories through malicious GitHub Actions workflows. The operation has been associated with the compromise of maintainer accounts, after which attackers inserted workflow logic designed to harvest secrets exposed to CI/CD environments. Reported theft included large volumes of credentials and tokens spanning package registries, source-code hosting, cloud services, container registries, and databases, creating downstream risk of package compromise, unauthorized publishing, and broader infrastructure access.
The campaign was observed affecting hundreds of repositories and multiple open-source ecosystems, including npm and PyPI packages. Its activity indicates an emphasis on automated, broad-spectrum secret collection rather than highly selective victim targeting. By abusing trusted development and release pipelines, GhostAction fits the pattern of modern supply-chain attacks in which compromise of developer or maintainer workflows can cascade into downstream consumers.
High-confidence reporting supports secret theft and data exfiltration as core behaviors. The available information does not establish a distinct malware family or implant with sufficient specificity beyond the malicious workflow-based tradecraft used in the campaign. GhostAction is best understood as a named supply-chain attack operation leveraging GitHub Actions for credential harvesting and post-compromise abuse of CI/CD trust relationships.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named attack tooling/campaign referenced as having compromised hundreds of repositories via automated abuse of GitHub Actions workflows.
Named supply-chain incident affecting the JavaScript/npm ecosystem (no further technical details provided in the content).
Malicious GitHub Actions workflow used in a supply chain attack to exfiltrate secrets and credentials from compromised repositories and projects.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.