Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Gaetan Ferry, Guillaume Valadon
Word Count
1,497
Company Posts That Month
8
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitGuardian uncovered the GhostAction campaign, a large-scale supply chain attack that compromised 327 GitHub user accounts to inject malicious workflows and steal 3,325 secrets from CI/CD environments across 817 repositories. The attackers disguised the workflows as "Github Actions Security" and extracted sensitive credentials, such as PyPI tokens, npm tokens, DockerHub credentials, GitHub tokens, and AWS access keys, via HTTP POST requests to a controlled endpoint. Despite the breach, no malicious packages were published using the stolen credentials, but 24 packages remain at immediate risk of compromise. GitGuardian's swift response involved alerting affected users, collaborating with GitHub, npm, and PyPI security teams, and maintaining surveillance to prevent further exploitation. Developers are advised to audit repository access, monitor for unauthorized changes, and implement additional security measures to protect against similar attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 26 1,019 166 73 -2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.