StepSecurity Says GhostAction Pushed Credential-Stealing Workflows to 345 Repositories via Two Hijacked Maintainer Accounts on October 8
StepSecurity says two hijacked maintainer accounts, including Uber athenadriver's author, pushed a credential-stealing workflow to 345 repositories on October 8; Socket counts 500+ accounts.
Editor's Note ·
- Clarification:
- The article says Socket's post could be read "only through a summarizing tool" and that it "dates the injections to October 7 and 8". The full Socket page was in fact captured and read directly during editorial review. Socket dates its analyzed burst of 346 repositories to October 8; October 7 appears only in its update about more than 500 accounts, which it says committed the workflow to tens of thousands of repositories since October 7.
Overview
Attackers running the GhostAction credential-theft campaign used two hijacked maintainer accounts on October 8, 2026 to push a malicious GitHub Actions workflow into 345 repositories, according to StepSecurity, which published its analysis on October 9. Repository counts differ slightly between researchers, and the broader tally is larger: Socket said it had identified more than 500 GitHub accounts that committed the workflow to tens of thousands of repositories since October 7, as relayed by The Hacker News. The figures below come from the vendor write-ups listed in the sources and have not been independently verified.
What We Know
The October 8 sweep. StepSecurity says the attacker used the account of Takashi Kitao, author of the 18,400-star game engine pyxel, to push the workflow to 27 repositories starting at 13:20 UTC. Eight hours later, it says, the account of Henry Wu (henrywoo), the original author of Uber’s athenadriver, was used to push the same workflow to 318 repositories between 21:10 and 21:26 UTC (StepSecurity). Of those 318, StepSecurity counts 39 source repositories and 279 forks. The Hacker News describes the push as reaching “over 340 repositories”, while GitGuardian, citing Socket, puts the burst at 346 repositories. GitGuardian also gives 18,420 stars for pyxel, against StepSecurity’s 18,400. Socket’s post, which the Machine Herald could read only through a summarizing tool, dates the injections to October 7 and 8, whereas StepSecurity dates both windows to October 8.
Disguise and access. The workflow is presented as a security audit and was committed under the victims’ own identities. StepSecurity says the commit in uber/athenadriver is unsigned and went straight to the default branch with no pull request or review, because Wu retained write access to the Uber organization repository (StepSecurity). On how the accounts were taken over, StepSecurity calls a leaked personal access token “most plausibly a leaked personal access token from infostealer logs or credential dumps”, and The Hacker News says “most likely”. Neither source confirms the actual route.
What is new. StepSecurity says this wave goes beyond the repository’s configured Actions secrets. Because the workflow checks out the full history, it can sweep every commit on every branch, and the working tree, for thirteen credential patterns (StepSecurity). The targets include AWS keys, Anthropic, OpenAI and OpenRouter API keys, and GitHub and GitLab tokens (The Hacker News). StepSecurity draws the consequence that rotating configured Actions secrets “no longer covers the exposure”, since a credential committed years ago and later deleted would still be found. The finding connects to earlier Herald coverage of live credentials left in public GitHub repositories, although that scan examined default branches only and did not look at commit history.
Execution. StepSecurity says the run log for uber/athenadriver shows the attacker’s server acknowledging receipt four seconds after the workflow started, and that the token in that run was limited to read access to repository contents, so the workflow could not itself push or publish. It adds that the pyxel workflow ran five times, all concluding in success, twice through manual triggers issued from the compromised session, and that the workflow referenced pyxel’s PyPI and crates.io publishing credentials, registries to which the project is dual-published (StepSecurity). GitGuardian says that, unlike the September wave, these October runs executed and that Socket confirmed successful exfiltration.
Packages unaffected, as of October 9. StepSecurity writes that no malicious package releases had been published from the compromised publishing credentials as of its writing, noting that pyxel’s last release was v2.9.9 on August 12, 2026, before the compromise. It cautions that “the absence of abuse so far is not evidence that the credentials are safe” (StepSecurity). The Hacker News likewise reports no malicious releases as of its writing.
Scale on October 9. StepSecurity reports that a GitHub code search on October 9 returned 378 repositories with a live malicious workflow on the default branch, 182 of which carried the history-mining marker. It calls the counts approximate and notes that code search excludes forks (StepSecurity).
The earlier wave. GitGuardian reports that between August 31 and September 30, 2026 the workflow was pushed to 772 public repositories belonging to 373 GitHub users and organizations, targeting 2,577 secrets. Of 3,669 runs it collected across 605 repositories, only 499 executed, in 32 repositories; 336 completed successfully, exfiltrating 26 secrets from 13 repositories. Only 124 repositories (16 percent) had been cleaned in observed public history by October 5, it says. GitGuardian writes that its data shows GhostAction “never really stopped”, and that the campaign first surfaced in September 2025 with 817 repositories across 327 users and at least 3,325 secrets stolen. StepSecurity gives the 2025 figure as more than 3,000 secrets.
One control that worked. In one repository, StepSecurity says, attacker commits meant to re-trigger the workflow stalled because the repository requires approval for workflow runs, and the exfiltration did not execute (StepSecurity).
What We Don’t Know
- Whether stolen credentials have been abused. StepSecurity and The Hacker News report no malicious package releases as of October 9; neither says what has been done with exfiltrated credentials.
- How the accounts were compromised. The leaked-token route is a researcher assessment, not a confirmed finding.
- The true scale. The tens-of-thousands figure and the 500-account count are Socket’s, as quoted by The Hacker News. StepSecurity and GitGuardian report counts in the hundreds for the October 8 burst and do not independently confirm the larger number.
- A link to cryptomining. GitGuardian describes a cryptominer commit in the kuafuai/DevOpsGPT repository on August 30, 2026, and says it is “not convinced” the GhostAction operator is behind it, noting that the two used the same compromised account but differ in almost everything else. The Hacker News describes the miner as an alteration by threat actors without drawing that distinction. GitGuardian’s view is that the GitHub credentials GhostAction uses are probably not exclusive to its operator.
Recommended Response
The vendors’ guidance is consistent. The Hacker News relays advice to check repositories for either of the two disguised workflows since August 31, 2026, to assume compromise if one is present, to revoke the compromised GitHub credential, to rotate credentials, to delete the malicious workflow from all branches and to check forks of infected repositories. StepSecurity adds that any secret ever committed to a repository should be treated as compromised, and GitGuardian warns that rotating exfiltrated secrets is not enough if the GitHub credential that allowed the injection is not found and revoked.