The campaign that never stopped: tracking GhostAction from 2025 to 2026
Blog post from GitGuardian
GitGuardian reports that the GhostAction software supply chain campaign, first identified in September 2025, continued through 2026 rather than ending, with a new wave compromising 772 public GitHub repositories across 373 users and organizations between late August and September. Attackers used apparently stolen GitHub credentials to commit malicious GitHub Actions workflows under victims’ identities, targeting secrets referenced in legitimate repository workflows and sending them via HTTP to a new server endpoint; although GitHub approval requirements prevented most executions, 336 successful runs exfiltrated 26 secrets from 13 repositories. The campaign targeted deployment, cloud, container registry, database, source-control, messaging, and other credentials, while public cleanup records indicate that relatively few affected repositories had removed the malicious workflows by early October. Historical workflow evidence also links the campaign to several earlier endpoints and shows attackers updating dormant malicious workflows left in repositories from prior waves. Separately, researchers found an XMRig cryptominer inserted into the DevOpsGPT project through the same compromised account later used for GhostAction, but concluded that the differing methods and tailored payload made a common operator uncertain. Additional overlap between GhostAction victims and unrelated cryptomining campaigns suggests that compromised GitHub credentials may circulate among multiple attackers, making revocation of the initial access credential as important as rotating any exposed secrets.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 13 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.