On 7 October 2026, GitGuardian reported a new wave of GhostAction, the GitHub Actions campaign it first exposed in September 2025. Between 31 August and 30 September 2026, the same fake "Github Actions Security" workflow was pushed to 772 public repositories belonging to 373 GitHub users and organisations. As in 2025, every commit was made under the victim's own identity using what GitGuardian says appear to be stolen credentials. The injected workflows named 2,577 secrets, led by SSH and deployment server credentials, Azure credentials and container registry logins. GitHub held most workflow runs for approval, which limited the damage: GitGuardian confirmed 26 secrets exfiltrated from 13 repositories. Only 124 repositories, about 16%, had been effectively cleaned by 5 October. GitGuardian argues the campaign never really stopped between waves. Reporting so far relies on GitGuardian's research, which other outlets have repeated.
Key takeaways
- GitGuardian found the GhostAction workflow pushed to 772 public repositories across 373 accounts between 31 August and 30 September 2026, with commits made under victims' own identities.
- The workflows targeted 2,577 secrets by name. GitGuardian confirmed 26 secrets exfiltrated from 13 repositories, because GitHub held most runs for approval.
- The most targeted secrets were SSH keys and deployment server credentials (446), Azure credentials (218) and container registry credentials (142). One organisation alone exposed an Azure PAT and an SSH key in 92 repositories.
- Only 124 repositories (16%) were effectively cleaned by 5 October 2026. In 92 cases the attacker edited workflows left over from earlier waves instead of adding new ones.
- The identity lesson: removing a malicious workflow is not the fix. The GitHub credential that pushed it must be found and revoked, or the same identity will be used again.
At a glance
| Organisations | 373 GitHub users and organisations with 772 public repositories, including the open-source project kuafuai/DevOpsGPT; one unnamed organisation with 92 affected repositories |
|---|---|
| When | Wave tracked from 31 August to 30 September 2026; disclosed by GitGuardian on 7 October 2026 |
| Attacker | Unknown. GitGuardian links it to the 2025 GhostAction campaign by its workflow and technique; Cynative researchers also spotted the commits |
| Entry point | Commits pushed with what appear to be stolen GitHub credentials, adding or modifying a workflow that sends secrets to an attacker server |
| Identities abused | Victims' GitHub credentials, then CI/CD secrets: SSH and deployment keys, Azure, AWS and Google Cloud credentials, container registry and database logins, GitHub, npm and PyPI tokens, bot tokens and AI provider keys |
| Impact | 2,577 secrets targeted; 26 secrets confirmed exfiltrated from 13 repositories; 84% of affected repositories not effectively cleaned by 5 October 2026 |
| Category | NHI. Incident class: confirmed NHI breach (stolen GitHub credentials used to exfiltrate CI/CD secrets) |
What happened
GhostAction first surfaced in September 2025, when GitGuardian found a fake security workflow in 817 repositories that had sent 3,325 secrets to an attacker. In its new research, published on 7 October 2026, GitGuardian's Gaetan Ferry wrote: "Our data shows that GhostAction never really stopped." Its data shows the operator kept injecting workflows through late 2025 and into 2026, switching between servers. "Calling this new wave a revival would be inaccurate," the post says. Researchers from Cynative also observed the new malicious commits and contacted GitGuardian.
The latest wave began on 31 August 2026 with 143 repositories, then about 400 between 2 and 5 September, peaking at 294 on 5 September, and 103 more on 15 September. Most commits used the original file name, github_actions_security.yml, and the commit message "Add Github Actions Security workflow". A smaller variant named security-check.yml appeared in seven repositories on 7 September. GitGuardian says "every commit was made with the victim's own identity, using what appear to be stolen credentials." Each workflow listed the secret names used by the repository's real pipelines and sent their values in one request to a bare IP address over plain HTTP. In 92 cases the attacker did not add a new file but edited a workflow left behind by an earlier wave.
Across the 772 repositories, the injected workflows targeted 2,577 secrets. GitHub's approval requirement for workflow runs blunted the attack. GitGuardian collected 3,669 runs across 605 repositories, of which 499 actually executed in 32 repositories. "In total, 336 runs completed successfully, exfiltrating 26 secrets from 13 repositories," it says, with new runs still triggering as it wrote. Cyber Press and GBHackers reported the same figures on 8 October 2026.
GitGuardian also found a cryptominer committed to kuafuai/DevOpsGPT, a project with about 6,000 stars, on 30 August 2026, and the GhostAction workflow pushed to four repositories in the same organisation on 15 September by the same account. The authors are not convinced the two are the work of one operator, because the miner commit used a forged author email. Thirteen GhostAction victim repositories were also used by at least four separate mining campaigns, which GitGuardian takes as a sign that leaked credentials are reused by unrelated actors. Clean-up has been poor: by 5 October only 124 repositories, about 16%, were effectively cleaned in public history.
Timeline
| Date | Event |
|---|---|
| 5 September 2025 | GitGuardian discloses the original GhostAction campaign: 817 repositories and 3,325 secrets. |
| 30 August 2026 | A cryptominer commit lands in kuafuai/DevOpsGPT. |
| 31 August 2026 | The new GhostAction wave begins with 143 repositories. |
| 5 September 2026 | Injections peak at 294 repositories in a day, part of about 400 between 2 and 5 September. |
| 7 September 2026 | A smaller security-check.yml variant appears in seven repositories. |
| 15 September 2026 | 103 more repositories are injected, including four in the DevOpsGPT organisation. |
| 5 October 2026 | GitGuardian finds only 124 repositories effectively cleaned. |
| 7 October 2026 | GitGuardian publishes its research on the 2026 wave. |
How it happened: the identity attack path
- Stolen developer credentials. The attacker held GitHub credentials for hundreds of users and organisations. How they were obtained has not been established.
- Secrets mapped from real workflows. For each repository, the attacker read the legitimate workflow files and copied the names of the secrets they used.
- Workflow planted or reused. A commit under the victim's identity added the fake security workflow, or edited one left from a previous wave.
- Secrets sent out on the next run. When the workflow ran, the runner decrypted the named secrets and the job posted them to the attacker's server.
- Credentials left live. Most affected repositories had not been cleaned by 5 October 2026, and workflows planted in earlier waves were still there to be reused, a sign that the access behind them had not been shut off.
Impact
- Confirmed: 26 secrets exfiltrated from 13 repositories through 336 completed workflow runs, according to GitGuardian.
- Exposed to theft: 2,577 secrets named in injected workflows across 772 repositories, including 446 SSH and deployment credentials, 218 Azure credentials and 106 AWS access keys. These are targets, not confirmed thefts.
- Compromised identities: the GitHub credentials of 373 users and organisations were used to push commits, and most had not been dealt with by 5 October 2026.
- Wider: victim repositories were also abused for cryptomining by other actors, suggesting the stolen credentials are shared or traded.
What this means for NHI governance
The 2026 wave shows what happens when an incident is not closed at the level of identities. Workflows planted in earlier waves were still sitting in repositories, and the attacker came back and edited them, which means the access used to plant them still worked. Only 16% of this wave's repositories had been effectively cleaned a month later. GitGuardian's advice is blunt: the GitHub credential that allowed the injection "must be found and revoked too," or "someone else will use it again."
The campaign also shows one control working. Requiring approval before workflows run held back most of the 3,669 runs. The longer-term fix is to make CI/CD secrets less valuable: short-lived credentials through OIDC instead of stored keys, deployment secrets limited to protected environments, and alerts when a workflow file changes. See our CI/CD Pipeline Identity Security Guide and Leaked Credential Response Playbook.
Recommendations
- Revoke the credential that pushed the commit. Find the token, SSH key or session behind each malicious commit and revoke it, then review its other activity. See the Leaked Credential Response Playbook.
- Rotate every secret the workflow named. Treat all secrets referenced by a planted workflow as exposed, even if you cannot see a successful run.
- Keep approval gates on workflow runs. Require approval for workflows triggered by new or outside contributors, and protect deployment secrets with environments and required reviewers. See our CI/CD Pipeline Identity Security Guide.
- Replace stored cloud keys with OIDC. Short-lived, workload-bound credentials leave nothing durable for a workflow to steal. See our Cloud Workload Identity Guide.
- Audit for leftovers from earlier waves. Search for
github_actions_security.ymlandsecurity-check.yml, including in history, across every repository you own. - Monitor workflow files as code that holds keys. Alert on new or changed files under
.github/workflowsand on runners making plain HTTP calls to bare IP addresses.
Frequently asked questions
Is GhostAction back in 2026?
Yes. GitGuardian reported on 7 October 2026 that the GhostAction workflow was pushed to 772 public repositories between 31 August and 30 September 2026. It says the campaign never really stopped after 2025, so this is a continuation rather than a revival.
How many secrets were stolen in the 2026 GhostAction wave?
The injected workflows targeted 2,577 secrets, but GitHub held most runs for approval. GitGuardian confirmed 26 secrets exfiltrated from 13 repositories, with new runs still triggering when it published.
Is deleting the GhostAction workflow enough?
No. The secrets the workflow named should be rotated, and the GitHub credential used to push the commit must be revoked. GitGuardian found 92 cases where the attacker reused a workflow left behind from an earlier wave.
Related NHI Mgmt Group resources
GhostAction Campaign 2025 · Megalodon GitHub Actions Attack 2026 · tj-actions/changed-files Compromise 2025 · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Repeat compromises usually mean the identity behind the first one was never revoked. We help teams trace malicious commits back to the credentials that made them, rotate pipeline secrets quickly and move CI/CD to short-lived credentials. See our NHI and AI agent security training.
References
- GitGuardian: The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows (5 September 2025)
- GitGuardian: The campaign that never stopped: tracking GhostAction from 2025 to 2026 (7 October 2026)
- Cyber Press: GhostAction Supply Chain Attack Hits 772 GitHub Repositories to Steal CI/CD Secrets (8 October 2026)
- GBHackers: Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens (8 October 2026)