A recent cybersecurity report has revealed details of an ongoing credential-theft operation that has compromised two prominent open-source maintainer accounts, leading to the insertion of a malicious workflow into over 340 repositories.
According to StepSecurity, the attacker utilized the accounts of Takashi Kitao and Henry Wu to push a malicious workflow named Security Audit or GitHub Actions Security to multiple repositories, resulting in the exfiltration of sensitive data.
Since October 7, 2026, Socket has identified more than 500 GitHub accounts involved in committing the malicious workflow to numerous repositories, marking the resurgence of the GhostAction campaign first detected in September 2025.
The malicious workflows are designed to extract GitHub Actions secrets, CI/CD secrets, and various cloud, AI, and SaaS credentials, posing a significant threat to the security of developers and organizations.
The attack process involves obtaining GitHub credentials, scanning repository workflows for secrets, injecting a disguised security audit workflow, and transmitting the extracted data to an attacker-controlled server.
The GhostAction campaign has targeted numerous public repositories, compromising a wide range of credentials such as SSH keys, Azure credentials, DockerHub tokens, and more. In some instances, threat actors have even embedded cryptocurrency miners into project Docker images.
Developers are urged to inspect their repositories for any signs of the malicious workflows, revoke compromised credentials, and take necessary security measures to protect their code and sensitive information.
It is crucial for the developer community to remain vigilant and proactive in safeguarding their projects against supply chain attacks like GhostAction, which continue to pose a serious threat to the integrity of open-source software.





