GhostAction Attack Escalates By Targeting GitHub Users OpenSourceMalware identified a new escalation of the GhostAction supply-chain campaign, in which attackers compromise GitHub accounts and inject malicious Actions workflows that steal CI/CD secrets, including package-publishing, cloud, GitHub, and AI-service credentials. The newer .github/workflows/security-audit.yml variant scans the full checkout and git history for credential-shaped strings, captures contextual lines around AWS keys, and POSTs the results over unencrypted HTTP to 193.32.204.199/?c=monami. Two newly registered domains, my-gitlab.com on September 22, 2026 and my-github.com on October 9, 2026, may signal a developer-targeting phishing wave, with my-github.com pointing directly to the active GhostAction collector IP. BLOG GhostAction Attack Escalates By Targeting GitHub Users OSM has identified a new evolution of the GhostAction attack, which targets GitHub users via malicious CI workflow files and worm-like behaviour By c0a15726-c5b1-4b0d-85e6-fe15553df9e2 · OpenSourceMalware has identified a new stage in the ongoing "GhostAction" malicious campaign that GitGuardian originally identified https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/ in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab. The GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/ Earlier today Socket https://socket.dev/blog/ghostaction-cloud-credentials and StepSecurity https://www.stepsecurity.io/blog/ghostaction-returns subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise. The established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer .github/workflows/security-audit.yml variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to 193.32.204.199/?c=monami . Responders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise. Early Warning: A Possible New Developer-Targeting Wave Two newly registered, code-hosting-themed domains may signal the next phase of developer targeting. my-gitlab.com was registered on September 22, 2026, followed 17 days later by my-github.com . The domains share the exact my-