Malicious GitHub workflows expose credentials across hundreds of repositories

Hackers have compromised hundreds of GitHub repositories by inserting malicious automation workflows designed to steal SSH keys, cloud credentials and access tokens, with security researchers confirming the theft of 26 secrets from 13 repositories.

Cybersecurity company GitGuardian identified 772 affected public repositories belonging to 373 users and organisations during an attack campaign spanning August 31 to September 30. The malicious workflows targeted 2,577 secrets, although the overwhelming majority of attempted thefts did not result in confirmed credential exposure.

The findings, published on October 7 by researchers Gaetan Ferry and Guillaume Valadon, document another wave of the GhostAction supply chain campaign, which exploits compromised developer credentials to insert unauthorised instructions into GitHub Actions, the platform’s automated software development system.

Researchers examined 3,669 workflow runs across 605 repositories and established that only 499 executions occurred in 32 repositories. Of those, 336 completed successfully, resulting in the confirmed exfiltration of 26 secrets.

GitHub’s approval mechanisms prevented most malicious workflows from executing automatically, substantially limiting the observed damage. However, the researchers found that unauthorised workflows remained embedded in numerous repositories, potentially exposing credentials whenever subsequent legitimate development activity triggered their execution.

The attackers disguised their instructions as security maintenance operations. One malicious file, named githubactionssecurity. yml, carried a commit message describing the addition of a GitHub Actions security workflow.

Rather than indiscriminately collecting every available environment variable, the attackers examined existing repository configurations to identify specific credential names. Their injected workflows then attempted to retrieve those values and transmit them through HTTP requests to infrastructure under their control.

A second variant appeared on September 7 across seven repositories, using the filename security-check. yml and presenting itself as a routine security check. Its communication mechanism incorporated identifiers that researchers believe allowed attackers to associate stolen credentials with individual repository compromises.

SSH private keys and deployment server credentials represented the largest targeted category, accounting for 446 entries. Azure credentials followed with 218, while container registry credentials accounted for 142 and database credentials for 112.

The attackers also targeted 106 AWS access keys, 92 FTP credentials, 80 Google Cloud and Firebase credentials, and 66 GitHub tokens. Additional targets included authentication information associated with messaging services, software package registries and artificial intelligence providers.

GitGuardian emphasised that the 2,577 targeted entries did not represent confirmed thefts. Some identified values, including hostnames and usernames, were not independently sensitive, although their collection alongside authentication credentials could assist further attacks.

The campaign unfolded through several concentrated bursts. Researchers identified 143 affected repositories on August 31, approximately 400 between September 2 and September 5, and another 103 on September 15.

Evidence of remediation remained limited. By October 5, only 124 affected repositories, representing approximately 16 per cent of the total, had been effectively cleaned in the public development history examined by researchers.

Investigators also identified 92 cases in which attackers modified malicious workflows already present from earlier compromises, replacing their communication destinations rather than introducing entirely new files.

The findings indicate that some repositories had remained vulnerable across successive attack waves, allowing compromised automation instructions to persist without detection or removal.

GitGuardian additionally identified suspicious cryptocurrency mining activity affecting the DevOpsGPT open-source project. An unauthorised modification introduced mining software into its Docker configuration before GhostAction workflows subsequently targeted repositories associated with the same organisation.

The project’s maintainers removed the malicious workflows on September 18 and reversed the cryptocurrency mining modification on October 4.

Researchers cautioned against assuming that both intrusions involved the same attacker. Although the incidents involved a shared compromised account, their technical characteristics differed, leaving responsibility for the mining operation unresolved.

GitHub’s security documentation advises repository administrators to restrict workflow permissions, audit credential handling and rotate exposed secrets. Compromised authentication tokens should also be revoked because removing malicious workflow files alone does not prevent attackers from regaining access through stolen credentials.

The investigation further identified 13 repositories affected by separate cryptocurrency mining operations involving at least four distinct campaigns. Researchers observed that mining activity sometimes preceded the credential theft attempts and sometimes followed them, illustrating how compromised accounts could be exploited independently by different operators.

GitGuardian’s earlier investigation documented 817 compromised repositories and at least 3,325 stolen secrets during the September 2025 GhostAction campaign, establishing the earlier scale of the operation.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…