Cyber-Attack Campaign GhostAction Targets GitHub Workflows

Security investigators uncovered a sweeping campaign named GhostAction supply chain campaign that compromised 327 GitHub user accounts across 817 repositories on 5 September 2025. Attackers inserted deceptive workflow files, disguised as security enhancements, into projects—including the open-source FastUUID library—extracting and exfiltrating 3,325 secrets such as PyPI, npm and DockerHub tokens to an external server.

The campaign began when GitGuardian noted a suspicious commit on 2 September by the GitHub user Grommash9. The change, titled “Add Github Actions Security workflow”, embedded a workflow that captured PyPI API tokens and sent them to a specified HTTP endpoint. Although the workflow was executed, no malicious package uploads were detected in the FastUUID project during the compromised timeframe. By midday on 5 September, PyPI placed the project into read-only mode, and the malicious commit was promptly reverted.

Further analysis revealed that this tactic was systematic: attackers inspected legitimate CI/CD pipelines within targeted repositories to identify secret names, then crafted tailored malicious workflows to capture credentials on push or manual trigger. In total, more than 3,300 secrets—spanning DockerHub credentials, personal access tokens, npm authentication tokens, PyPI keys, AWS credentials, database logins, and Cloudflare API tokens—were stolen across over eight hundred repositories.

This breach exposed a critical weakness in the current CI/CD security model: the assumption that automated workflows are inherently benign. The GhostAction supply chain campaign underscores how trusted automation can be weaponised to harvest sensitive credentials undetected.

Developers and organisations need to urgently enforce stricter controls over GitHub Actions. Measures such as mandatory code reviews for workflow changes, branch protection rules, automated secret scanning and frequent rotation of credentials are vital to mitigate such threats.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Wuxi Symphony Orchestra Debuts at Ljubljana Festival: Sounds of the East Illuminate the Historic Central European City // TDCX expands Hyderabad footprint with second campus // Iran braces for sweeping US economic offensive // MyRepublic expands GAMER lineup with Dreamcore x MyRepublic RTX 5060 Ti Gaming PC and Limited Edition ASUS T1 Graphics Card Broadband Bundle // From Vietnam to the U.S: East West Barbershop takes on the world’s most competitive market // TDCX Opens Second Hyderabad Campus, Reinforcing India as Key Global Delivery Hub // North Korea-linked hackers target Rust software supply chain // Silence Wang Wax Figure Arrives at Madame Tussauds Hong Kong // Standard Chartered takes HKDAP into banking mainstream // Iran rial sinks beyond two million per dollar // ADNOC Distribution brings Reatile into Shell deal // NASA images expose crater from Falcon 9 crash // Objective Digital Psychological Assessment Launches in Singapore, Offering Clarity for Inattention and Hyperactivity Concerns // MoreTickets Reveals Hong Kong’s Top-Searched Summer Events and Evolving Ticket-Buying Behaviours // AI sharpens cyber battle across financial markets // 5G Capital Sets a New Benchmark:China Unicom Beijing and Huawei Power the 2nd World Humanoid Robot Games with 5G-A GigaUplink // Onix builds expert-led AI around trust and privacy // MacSync rotates domains as macOS credential theft expands // 40 Teams Gather in Hong Kong to Compete in the “AI x Cybersecurity Challenge” // Jharkhand may witness a more complicated students movement //