Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› GhostAction Campaign 2025: How Compromised GitHub Accounts Planted…
Breach analysis Incident: 5 Sep 2025

GhostAction Campaign 2025: How Compromised GitHub Accounts Planted Workflows That Stole 3,325 CI/CD Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
On this page

In early September 2025, GitGuardian uncovered GhostAction, a campaign that used compromised GitHub accounts to add a malicious GitHub Actions workflow to 817 repositories belonging to 327 users. The workflow, disguised as a "Github Actions Security" check, read the names of secrets already used by each repository's legitimate pipelines and sent their values to an attacker server. GitGuardian counted 3,325 stolen secrets, led by DockerHub credentials, GitHub tokens and npm tokens, and said several companies had their entire SDK portfolio affected. It was first spotted on 5 September 2025 in the FastUUID project, where the first malicious commit had been pushed on 2 September and the project's PyPI publishing token was taken. GitGuardian said 24 npm and PyPI packages were at immediate risk of malicious releases, though none were seen. The exfiltration endpoint went offline the same day. How the attacker obtained the GitHub accounts is unknown.

Key takeaways

  • GitGuardian found a malicious workflow pushed to 817 repositories across 327 GitHub users, which exfiltrated 3,325 secrets to an attacker-controlled server.
  • The attacker first read the secret names used by each repository's real workflows, then hardcoded them into a new workflow so the pipeline handed over exactly those values.
  • Stolen secrets included DockerHub credentials, GitHub tokens, npm and PyPI tokens, AWS access keys, database credentials and Cloudflare API tokens. GitGuardian told SecurityWeek attackers were actively exploiting some of them.
  • Commits were made under the victims' own GitHub identities. GitGuardian said "the initial attack vector remains unknown", and the same technique returned in a larger 2026 wave.
  • The identity lesson: anyone who can push a workflow file inherits every secret the pipeline can read, so a stolen developer credential is also a stolen CI/CD credential.

At a glance

Organisations327 GitHub users and 817 repositories, including FastUUID on PyPI and several unnamed companies whose SDK repositories in Python, Rust, JavaScript and Go were affected
WhenFirst malicious commit 2 September 2025; discovered and disclosed 5 September 2025; second smaller wave 9 September 2025
AttackerUnknown. GitGuardian found no overlap with the S1ngularity (Nx) victims and believes the two campaigns are likely unrelated
Entry pointCompromised GitHub maintainer accounts used to push a workflow named github_actions_security.yml; how the accounts were compromised is unknown
Identities abusedThe maintainers' GitHub identities, then CI/CD secrets stored in GitHub Actions: DockerHub, GitHub, npm and PyPI tokens, AWS keys, database and Cloudflare credentials
Impact3,325 secrets exfiltrated; 24 npm and PyPI packages at risk of malicious releases, none observed; some stolen AWS and database credentials reported as actively exploited
CategoryNHI. Incident class: confirmed NHI breach (CI/CD secrets stolen through compromised GitHub accounts)

What happened

On 2 September 2025, a GitHub account belonging to a maintainer of FastUUID, a Python library, pushed a commit titled "Add Github Actions Security workflow". GitGuardian's monitoring flagged it on 5 September. The new workflow ran on every push and could also be started by hand. After a dummy step, it used curl to post the repository's secrets to an attacker-controlled server. In FastUUID's case that included the PyPI token the legitimate pipeline used to publish releases. SecurityWeek summarised: "In the case of the FastUUID project, the attacker obtained a PyPI token used for package deployment." No malicious FastUUID release appeared, and PyPI put the project into read-only mode at 12:11 that day.

GitGuardian then searched for the same commit elsewhere and found a much larger campaign. Its researchers, Gaetan Ferry and Guillaume Valadon, counted 817 repositories across 327 users. They found that "The attacker first enumerated secrets from legitimate workflow files", then wrote those secret names into each malicious workflow, so it asked the pipeline for exactly the credentials the project used. In total 3,325 secrets were sent out. The most common were DockerHub credentials, GitHub tokens and npm tokens, followed by PyPI tokens, AWS access keys, database credentials and Cloudflare API tokens. GitGuardian said "Several companies were found to have their entire SDK portfolio compromised", and that 9 npm and 15 PyPI packages were at immediate risk because their publishing tokens had been taken.

The response was quick. GitGuardian notified GitHub, npm and PyPI at 15:50 on 5 September, and the exfiltration hostname stopped resolving at 16:15. Of the 817 repositories, 100 had already reverted the change, and GitGuardian opened issues in 573 of the remaining 717. A second wave on 9 September added about 500 commits, mostly to repositories already hit, plus 14 new ones. StepSecurity, reviewing the case, wrote that "The workflow's simplicity was its strength". GitGuardian told SecurityWeek that, based on early discussions with affected developers, "attackers were actively exploiting the stolen secrets, including AWS access keys and database credentials". GitGuardian said "the initial attack vector remains unknown". In October 2026 it reported a new wave using the same workflow, covered on a separate page.

Timeline

DateEvent
2 September 2025A compromised FastUUID maintainer account pushes the "Add Github Actions Security workflow" commit.
5 September 2025GitGuardian detects the commit, PyPI makes FastUUID read-only, and GitHub, npm and PyPI are notified; the exfiltration endpoint stops resolving.
5 September 2025GitGuardian and StepSecurity publish details: 327 users, 817 repositories, 3,325 secrets.
8 September 2025SecurityWeek reports the campaign and GitGuardian's warning that stolen secrets were being exploited.
9 September 2025A second wave adds about 500 commits and reaches 14 new repositories.
15 September 2025GitGuardian updates its report with the second wave and new endpoints.

How it happened: the identity attack path

  1. Developer identities compromised. The attacker gained push access to GitHub accounts of maintainers and organisation members. How is unknown.
  2. Secrets mapped. The attacker read each repository's legitimate workflow files to learn the names of the secrets it used.
  3. Workflow planted. A new workflow, committed under the victim's own identity, requested those named secrets and ran on the next push.
  4. Secrets sent out. The pipeline decrypted the secrets for the job, and the workflow posted them to an attacker server with curl.
  5. Stolen tokens in hand. The attacker held publishing tokens for 24 npm and PyPI packages, registry credentials and cloud keys, some of which were reported as exploited.

Impact

  • Confirmed: 3,325 secrets exfiltrated from 817 repositories belonging to 327 GitHub users, according to GitGuardian.
  • Reported misuse: GitGuardian told SecurityWeek that stolen AWS access keys and database credentials were being actively exploited, based on discussions with affected developers.
  • Potential: malicious releases of 24 npm and PyPI packages using stolen publishing tokens. GitGuardian said none had been seen at the time of writing and it was monitoring the registries.
  • Wider: several companies had workflows planted across their SDKs in four languages, so their customers' supply chain was at risk until tokens were rotated.

What this means for NHI governance

GhostAction did not need a vulnerability in GitHub Actions. It used the pipeline exactly as designed: anyone who can commit a workflow file can ask for the repository's secrets, and the runner will hand them over. That makes every GitHub account with write access a path to every CI/CD secret, including publishing tokens, registry passwords and cloud keys. Those secrets are often long-lived, shared across projects and rarely rotated, so a single compromised developer credential exposes a whole set of machine identities.

The defence is to shrink what a pipeline can hand over and to watch for changes to the pipeline itself. Short-lived credentials issued through OIDC, environment protection rules that limit secrets to specific branches, and alerts on new or changed workflow files would each have blunted this campaign. See our CI/CD Pipeline Identity Security Guide and Leaked Credential Response Playbook.

Recommendations

  • Rotate every secret the workflow requested. Treat all secrets named in a planted workflow as stolen, and revoke the GitHub credential used to push it. See the Leaked Credential Response Playbook.
  • Replace static CI secrets with OIDC. Use short-lived, workload-bound credentials for cloud access and trusted publishing for package registries. See our CI/CD Pipeline Identity Security Guide.
  • Gate secrets behind protected environments. Limit publishing and deployment secrets to protected branches and required reviewers, so a push to any branch cannot read them.
  • Alert on workflow changes. Require code owner review for .github/workflows and monitor for new workflow files and unusual outbound calls from runners.
  • Protect developer accounts. Enforce phishing-resistant MFA and short-lived, fine-grained tokens for everyone with write access. See our Secrets Management Guide.

Frequently asked questions

What was the GhostAction campaign?

GhostAction was a September 2025 attack in which compromised GitHub accounts added a fake "Github Actions Security" workflow to 817 repositories. The workflow sent each repository's CI/CD secrets to an attacker server, and GitGuardian counted 3,325 secrets stolen.

What secrets were stolen in GhostAction?

The most common were DockerHub credentials, GitHub tokens and npm tokens. GitGuardian also found PyPI tokens, AWS access keys, database credentials and Cloudflare API tokens, and said publishing tokens for 24 npm and PyPI packages were taken.

GitGuardian found no overlap with the victims of the S1ngularity (Nx) attack and believes they are likely unrelated. The Shai-Hulud worm, which appeared ten days later, used a similar workflow technique, but no shared operator has been established.

GhostAction Returns 2026 · Shai-Hulud npm Worm, First Wave · Megalodon GitHub Actions Attack 2026 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Pipeline secrets are among the least governed non-human identities in most organisations. We help teams inventory them, replace static tokens with short-lived credentials and build a fast rotation plan for when a workflow is tampered with. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org