The GhostAction supply-chain campaign has resurfaced, pushing a malicious GitHub Actions workflow into 772 public repositories belonging to 373 GitHub users and organizations between August 31 and September 30, 2026, according to a GitGuardian investigation published this week. Researchers at Cynative independently observed the malicious commits and alerted GitGuardian to the new wave.

The technique is unchanged from the wave GitGuardian first documented in September 2025, which compromised 817 repositories and exfiltrated at least 3,325 secrets: a workflow file named github_actions_security.yml is committed to the victim repository — under the victim's own identity, using what appear to be previously stolen credentials — with the commit message "Add Github Actions Security workflow." The workflow then sends named secrets in a single curl POST to the attacker's server. It is an abuse of repository access and CI/CD permissions, not a vulnerability in GitHub Actions itself.

The notable evolution is in exfiltration infrastructure. Instead of dumping every environment variable, the attacker scrapes the repository's legitimate workflow files and configuration history for specific secret references — deployment hosts, SSH private keys, usernames — and hardcodes exactly those names into the theft workflow. The new wave sends the values over plain HTTP to a bare IP address, 193.32.204.199. A September 7 variant observed in seven repositories uses security-check.yml and posts to an API endpoint carrying a unique per-injection identifier, suggesting a backend that tracks which injection each stolen secret came from.

Scale versus success

GBHackers' reporting on the research draws the useful distinction between targeting and theft. The workflows targeted 2,577 secrets — SSH keys and deployment credentials (446) topped the list, followed by Azure credentials (218), container registry credentials (142), database credentials (112) and AWS access keys (106) — but targeting did not always translate into exfiltration. Across 605 repositories, GitGuardian collected 3,669 workflow runs: GitHub held most for approval, 499 executed across 32 repositories, and 336 completed successfully. Researchers confirmed exfiltration of 26 secrets from 13 repositories. Most runs were triggered not by the attacker but by victims' own legitimate commits, because the malicious workflows remained configured to fire on every push.

Cleanup lags badly. As of October 5, only about 124 repositories — roughly 16 percent of those affected — showed effective remediation in observable public history. In 92 cases, attackers updated existing malicious workflows rather than adding new files, redirecting older payloads to fresh infrastructure. And the campaign overlaps with the broader credential-theft ecosystem: the same technique appeared in the Shai-Hulud npm campaigns and remains part of the Mini Shai-Hulud malware family; GitGuardian also found an XMRig cryptominer concealed in the Dockerfile of one victim project before its GhostAction compromise, and thirteen victim repositories overlapped with at least four distinct cryptomining campaigns.

For crypto and Web3 development teams the exposure is concrete: CI/CD pipelines routinely hold deployer keys, RPC endpoints, exchange API credentials and signing infrastructure. GitGuardian's guidance is standard but worth repeating — remove unauthorized workflows, revoke and rotate every exposed credential, and audit repository access and published artifacts. Workflow removal alone does nothing about secrets already stolen, nor about the compromised credentials that enabled the injection in the first place.

The structural lesson of GhostAction's return is that supply-chain attacks against developers don't need to be novel to keep working. A year after the original disclosure, an identical playbook with a fresh IP address still found 772 victims — and 84 percent of them hadn't cleaned up a week after the campaign's peak.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.