GhostAction Mines Git History: 500 GitHub Accounts Hijacked Socket researchers identified over 500 compromised GitHub accounts spreading a malicious "security-audit.yml" workflow to tens of thousands of repositories in the GhostAction campaign, which on October 8, 2026 saw two hijacked maintainer accounts push the file to 346 GitHub repositories in under 30 minutes. The October 2026 variant uses actions/checkout@v4 with fetch-depth: 0 and runs git log -p --all with 13 regex patterns to harvest credentials from entire git histories, including secrets deleted years ago, exfiltrating them to a plain HTTP endpoint at 193.32.204[.]199. GitGuardian found only 16% of repositories affected in the August–September 2026 wave, which extracted 2,577 secrets from 772 repos, were fully cleaned by October 5. On October 8, 2026, two hijacked maintainer accounts pushed a fake “security audit” workflow to 346 GitHub repositories in under 30 minutes. By the following day, Socket researchers https://socket.dev/blog/ghostaction-cloud-credentials identified over 500 compromised GitHub accounts spreading the same file to tens of thousands of repos. The campaign — dubbed GhostAction — is active right now, and its October 2026 variant has a feature that makes prior waves look tame: it mines your entire git history for credentials you deleted years ago. The Git History Twist That Changes Everything Previous GhostAction waves extracted only named GitHub Actions secrets from existing workflow configs. The October variant does something worse. The malicious security-audit.yml uses actions/checkout@v4 with fetch-depth: 0 — pulling every branch, every tag, every commit into the runner’s working directory. It then runs git log -p --all with 13 regex patterns targeting AWS keys, Anthropic API keys sk-ant- , OpenAI keys sk-proj- , GitHub PATs, GitLab tokens, Google Cloud credentials, Slack tokens, SendGrid, and package publishing credentials for PyPI, npm, and crates.io. The consequence is stark. As StepSecurity’s analysis https://www.stepsecurity.io/blog/ghostaction-returns confirmed: “a secret committed once in 2019 and deleted the next day is harvested just the same.” AWS keys are paired with their corresponding secret keys using surrounding context ±2 lines , demarcated by AKIA CTX START / AKIA CTX END markers for precision. The workflow triggers on unfiltered push events and manual dispatch — no approval gate, no friction. This is the attack that punishes developers who do the right thing. If you committed a key, noticed it, rotated it, and deleted it five years ago, you’re as exposed as someone with a live secret sitting in their Actions settings today. What Got Hit and What’s at Risk Two high-profile maintainer accounts were the entry point. Takashi Kitao — author of kitao/pyxel , a Python game engine with 18,420 GitHub stars — had 27 repositories compromised. Henry Wu henrywoo , author of pyllama and chatllama and original author of Uber’s athenadriver , had 318 repositories poisoned in 16 minutes. The exfiltration destination is a plain HTTP endpoint at 193.32.204 . 199 — the same C2 infrastructure used in the August–September 2026 wave that extracted 2,577 secrets from 772 repos. AI API keys are among the highest-value targets. A stolen Anthropic or OpenAI key isn’t just a billing problem — it can be used to inject malicious completions into AI-powered pipelines or exfiltrate data from models operating with sensitive context. No poisoned packages on PyPI or crates.io were confirmed as of October 9, but maintainer credentials for those registries are in scope, and that window is closing. Related: Megalodon: 5,561 GitHub Repos Backdoored in Six Hours — Rotate Your CI Secrets Now https://byteiota.com/megalodon-github-actions-cicd-attack/ Rotating Your Secrets Is Step One, Not the Fix The most critical point from the security research: rotating only the exfiltrated credentials is not enough. The GitHub credential — a personal access token or OAuth token — that gave the attacker write access to your repository must also be revoked. If that PAT is still valid, the attacker can reinject the workflow tomorrow. GitGuardian found that only 16% of repositories affected in the August–September wave were fully cleaned by October 5. The campaign reuses the same infrastructure; it is not slowing down. The broader lesson is about credential debt. Git history accumulates secrets across years: hardcoded keys from a “temporary” test that never got cleaned, tokens pasted into a config during an outage, development secrets in a pre-push commit that got rebased but not purged from history. The Hacker News coverage https://thehackernews.com/2026/10/credential-stealing-github-actions.html confirmed GhostAction has been running continuously since September 2025, with each wave introducing new capability. The git history sweep is the attacker group catching up to what security researchers have warned about for years. What GitHub Repository Owners Must Do Right Now If you maintain a public GitHub repository, run through this checklist today. Speed matters — the exfiltration window is open and the campaign is still active. 1. Search for the workflow file. Check for .github/workflows/security-audit.yml or github actions security.yml added after August 31, 2026. If present, assume full breach. 2. Revoke all GitHub access. Invalidate every active session, personal access token, and SSH key. Enforce phishing-resistant MFA immediately. 3. Rotate secrets — live and historical. Every secret referenced in any workflow file. Then run Gitleaks or TruffleHog against your full git history https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack-returns/ to catch credentials in old commits. 4. Check package releases. If you publish to PyPI, crates.io, or npm, audit release history for versions you did not push. 5. Review your forks. Forks inherit workflow files. If your repo is a fork of an affected project, confirm the file did not propagate. 6. Enable GitHub secret scanning with push protection. It will not retroactively catch this attack, but it blocks future credential commits. 7. Block the C2 IP. Add 193.32.204 . 199 to your egress deny list at the runner and network level. Key Takeaways - GhostAction’s October 2026 wave is the fourth escalation of an ongoing campaign — it is active now, with 500+ compromised accounts and tens of thousands of repos in scope. - The git history mining feature means credentials deleted years ago are as exposed as live secrets. Rotating active keys alone is not a complete response. - The GitHub credential used to inject the workflow must be revoked — otherwise the attacker can reinject after cleanup. - AI API keys are explicit targets. Anthropic, OpenAI, and OpenRouter credentials in any workflow or git commit are in scope. - No confirmed downstream package poisoning as of October 9, but PyPI, crates.io, and npm publishing tokens are compromised in some cases — act before that changes.