• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials

Admin by Admin
October 11, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A brand new GhostAction marketing campaign has expanded to greater than 500 compromised GitHub accounts and has injected malicious workflows into tens of hundreds of repositories since October 7, 2026.

Socket’s October 9 replace describes a credential theft operation focusing on GitHub Actions secrets and techniques, cloud credentials, and AI service API keys embedded in supply code and repository historical past.

An initially analyzed October 8 burst affected 346 repositories by way of compromised maintainer accounts henrywoo and kitao.

GhostAction Hackers Compromise 500+ GitHub Accounts

Targets included uber/athenadriver and kitao/pyxel, exposing how contributor permissions can lengthen an account compromise into organization-owned tasks. Socket didn’t decide how attackers obtained the preliminary maintainer credentials.

Attackers dedicated .github/workflows/security-audit.yml on to repository default branches utilizing messages reminiscent of “Add safety audit workflow.”

Regardless of its reassuring title, the workflow harvests credentials. It runs on push occasions with out department or path restrictions and helps handbook execution by way of workflow_dispatch.

Earlier than deployment, attackers apparently inspected current workflows to establish referenced Motion secrets and techniques, then inserted these names right into a reusable payload.

In Pyxel, the workflow focused CARGO_REGISTRY_TOKEN, PERSONAL_ACCESS_TOKEN, PYPI_PASSWORD, and PYPI_USERNAME, creating potential publicity throughout GitHub, PyPI, and crates.io. The uniform payloads and compressed deployment home windows counsel automated enumeration and injection.

The brand new variant provides a repository scanning stage alongside the established Actions secret theft mechanism.

Utilizing actions/checkout@v4 with fetch-depth: 0, it retrieves historical past throughout branches and tags, then examines working-tree information and patch output from git log -p --all. Its historical past buffer is capped at 200,000 traces.

13 credential patterns cowl AWS entry identifiers, secret keys and session tokens; Anthropic, OpenAI and OpenRouter API keys; GitHub and GitLab tokens; and Google, Slack and SendGrid credentials.

Historic scanning can uncover secrets and techniques faraway from present information however nonetheless retained in reachable commits. The payload additionally captures two surrounding traces on both aspect of AWS entry key identifiers.

This context can expose adjoining secret entry keys, serving to attackers get well usable credential combos slightly than remoted identifiers. Collected knowledge and repository identifiers are transmitted collectively by way of a cleartext HTTP POST to hxxp://193.32.204[.]199/?c=monami.

Socket confirmed profitable workflow runs in affected repositories, with Pyxel offering the clearest publishing-credential focusing on instance. Nevertheless, researchers had noticed no malicious PyPI or crates.io releases attributable to this exercise.

Defenders ought to take away injected workflows, evaluation execution logs, revoke compromised account entry, and rotate uncovered credentials. Response should cowl each Actions secrets and techniques and dedicated credentials, together with historic exposures.

Socket additionally recommends auditing package deal releases, reviewing AWS CloudTrail exercise, blocking the exfiltration deal with, enabling secret scanning with push safety, and inspecting affected forks earlier than enabling Actions. Group-wide checks ought to comply with account permissions.

Class Indicator Description
Workflow file path .github/workflows/security-audit.yml Malicious workflow file masquerading as a safety audit.
Workflow file path .github/workflows/github_actions_security.yml Different malicious workflow file path.
Commit message Add safety audit workflow Commit message related to malicious workflow injection.
Commit message Replace safety audit workflow Commit message related to malicious workflow updates.
Commit message Add Github Actions Safety workflow Different commit message related to workflow injection.
Request physique marker REPO= Identifies the repository within the exfiltration request physique.
Request physique marker AKIA_CTX_START Marks the start of collected AWS credential context.
Request physique marker AKIA_CTX_END Marks the top of collected AWS credential context.
Community — C2 IP deal with 193.32.204[.]199 Attacker-controlled vacation spot used for credential exfiltration.

Observe: IP addresses and domains are deliberately defanged (e.g., [.]) to forestall unintentional decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms reminiscent of MISP, VirusTotal, or your SIEM.

Be a part of 16,000+ SOC groups utilizing ANY.RUN to streamline risk investigations and scale back handbook effort. Discover on your group 

Tags: AccountsAPICloudCompromisecredentialsGhostActionGithubhackersSteal
Admin

Admin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Getting Began with MLFlow for LLM Analysis

Getting Began with MLFlow for LLM Analysis

June 28, 2025
Over 70 Malicious npm and VS Code Packages Discovered Stealing Information and Crypto

Over 70 Malicious npm and VS Code Packages Discovered Stealing Information and Crypto

May 26, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Finest Voice Cloning APIs in 2026: Speaker Similarity, Consent Checks, and Value per 1M Characters

Finest Voice Cloning APIs in 2026: Speaker Similarity, Consent Checks, and Value per 1M Characters

September 21, 2026
High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

August 9, 2026
The ten Finest Films That Get Synthetic Intelligence Proper

The ten Finest Films That Get Synthetic Intelligence Proper

May 27, 2026
11 social media tendencies each marketer ought to watch in 2026 [new data]

11 social media tendencies each marketer ought to watch in 2026 [new data]

September 12, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials

GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials

October 11, 2026
The best way to construct a scalable technique

The best way to construct a scalable technique

October 11, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved