← Back to news
The Hacker News9 Oct 2026 · 2 min read

Malicious GitHub Actions Workflows Linked to Broad Credential-Theft Campaign

Security researchers say a credential-harvesting campaign has inserted malicious GitHub Actions workflows into repositories controlled by compromised open-source maintainers, potentially exposing CI/C...

Security researchers say a credential-harvesting campaign has inserted malicious GitHub Actions workflows into repositories controlled by compromised open-source maintainers, potentially exposing CI/CD secrets and other credentials.

StepSecurity reported that attackers used two maintainer accounts to add similarly named workflow files to hundreds of repositories. One account associated with the Pyxel game engine reportedly received the malicious workflow in 27 repositories, while another account was used to push it to more than 300 repositories within minutes.

Researchers at Socket said the wider activity may involve more than 500 GitHub accounts and tens of thousands of affected repositories since October 7. The operation has been linked by researchers to the previously identified GhostAction supply-chain campaign.

How the workflows operate

The injected files were presented as security-related automation and used names including security-audit.yml and github_actions_security.yml. According to the reports, the workflows can run after pushes or manual activation, check out the full repository history, search files and commits for credential patterns, and transmit collected data to an attacker-controlled server over unencrypted HTTP.

  • GitHub Actions secrets configured for a repository
  • Cloud and CI/CD credentials, including AWS keys and registry tokens
  • API keys for AI services and SaaS platforms
  • GitHub and GitLab tokens, SSH keys, and other credentials committed to source history

The workflow reportedly scans both the active working tree and historical commits, increasing the risk that secrets removed from current code could still be collected. Researchers said the attackers may have initially gained access through stolen personal access tokens obtained from credential dumps or infostealer malware logs.

Organizations should review repositories for the identified workflow names and unexpected workflow changes dating back to late August. If a malicious file is found, security teams should treat the repository as potentially compromised, revoke and replace GitHub credentials, rotate exposed secrets, remove the workflow from every branch, and inspect forks and downstream mirrors.

Forks may remain a source of risk because subsequent pushes can trigger the malicious automation when GitHub Actions is enabled. Researchers also noted that compromised accounts were allegedly used in at least one instance to add cryptocurrency-mining code to a container image, though no malicious package releases had been confirmed at the time of reporting.

Share this article:TwitterLinkedIn