HomeSecurityGhostAction campaign steals 3325 secrets in GitHub attack

GhostAction campaign steals 3325 secrets in GitHub attack

GitGuardian has uncovered a new software supply chain attack campaign, dubbed GhostAction, that extracted thousands of sensitive credentials before being detected and contained on September 5. The attackers exploited GitHub Actions workflows, automated processes defined in a GitHub repository in response to specific events, to steal 3,325 secrets from 327 users across 817 repositories.

See also: Salesloft Drift attack linked to GitHub breach

GhostAction
GhostAction campaign steals 3325 secrets in GitHub attack

“The GitGuardian security research team was internally notified of a possible compromise of a GitHub repository related to the FastUUID,” GitGuardian security researchers Gaetan Ferry and Guillaume Valadon said in a blog post. “Investigations revealed that a malicious GitHub workflow file had been inserted into the project.”

The compromised user pushed identical malicious commits to other public and private repositories. The stolen credentials include PyPI, npm, DockerHub, GitHub tokens, and more — delivered via HTTP POSTs to a checkpoint controlled by the attacker.

The GhostAction campaign appeared in the Python FastUUID project, where a contributor with the alias 'Grommash9' introduced a workflow modification on September 2. The modification contained code that extracted sensitive tokens, such as PYPI_API_TOKEN, and transmitted them via HTTP POST requests to a domain controlled by the attacker. Researchers later found similar malicious workflows in at least five public repositories and an estimated ten private ones.

See also: Water Curse uses GitHub accounts to distribute malware

GhostAction campaign steals 3325 secrets in GitHub attack
GhostAction campaign steals 3325 secrets in GitHub attack

The attack was highly adaptive, targeting environment-specific secrets, from container registry credentials to cloud provider keys. “The attack pattern remained consistent across projects. The attacker first enumerated secrets from legitimate workflow files and then incorporated these secret names into malicious workflows,” the researchers added in the blog post.

GhostAction extracted thousands of sensitive tokens that could have been used for package tampering, unauthorized access to infrastructure, or further supply chain breaches. The GitGuardian security team reacted quickly upon detection, and the FastUUID package was made read-only by PyPI maintainers within minutes. The malicious commit was reversed shortly thereafter.

GitGuardian notified the maintainers of the affected repositories, successfully contacting 573 projects, while also alerting the security teams at GitHub, npm, and PyPI to monitor for abuse. While no malicious packages have yet been published to official registries, GitGuardian said some packages may still be at risk. The blog shared a list of indicators of the breach, including network and GitHub Workflow.

See also: Hacker targets other hackers and gamers with hidden GitHub code

GhostAction campaign steals 3325 secrets in GitHub attack

For additional protection, the researchers stressed the importance of reviewing repository workflows, rotating exposed credentials, and adopting stricter controls for GitHub Actions to prevent similar incidents in the future.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS