Threats & Adversaries · Credential Theft

GhostAction raided GitHub history for credentials

Socket.dev says GhostAction altered a GitHub Actions workflow across 346 repositories, moving beyond CI/CD secret theft to pull cloud and AI credentials from source code and full git history. The campaign touched repositories including uber/athenadriver and kitao/pyxel, then sent what it found to a hardcoded IP.

The trick was to make the build job search the checked-out repo and its commit history inside the trusted CI context, where it can see more than the live tree. That means credentials deleted from current files can still be collected from older commits and reused.

For teams that let Actions read the repository, the exposure lives in history as well as in the workflow file. Cleaning the branch does not erase secrets that were ever committed, so a compromised repo can keep feeding follow-on access until those credentials are rotated.

2 sources · Oct 9

Timeline

Sources

Part of the PlainSec briefing for 2026-10-09

Every edition of this story: GhostAction raided GitHub history for credentials

More from today