Minacce · 9 ore fa
GhostAction ha colpito 346 repository GitHub e ha allargato il furto oltre i segreti di CI/CD: ora estrae credenziali cloud e AI anche dal sorgente e dalla cronologia git. Per chi usa GitHub Actions, il problema non è più il solo workflow alterato, ma l’intero set di segreti che può essere letto dentro il contesto fidato della build.
La campagna modifica un workflow di GitHub Actions per far cercare al job i segreti nel codice e nella storia completa del repository, poi li invia in chiaro a un IP hardcoded. Così una credenziale rimossa dal ramo corrente può restare recuperabile dai commit passati e diventare ancora riutilizzabile.
Per team DevOps e security che tengono segreti in codebase, configurazioni di build o history, la conseguenza è netta: cancellare un secret dal tree attivo non elimina l’esposizione. Se è mai finito nel repository, va trattato come compromesso finché non è ruotato.
2 fonti che coprono questa storia
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
More than 500 GitHub accounts committed credential-stealing workflows to tens of thousands of repositories since October 7, Socket says.
New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.
Part of the PlainSec briefing for 2026-10-09