GhostAction has escalated into a more aggressive supply-chain campaign that injects malicious GitHub Actions workflows into any writable repository a compromised account can reach. The payloads (github_actions_security.yml, security-audit.yml, security-check.yml) read named Actions secrets, scan the working tree and full git history for credential-like strings, and POST stolen secrets and surrounding context over HTTP to 193.32.204.199. Attackers enumerate writable repos, push workflows directly without review, trigger executions (push or workflow_dispatch), and then reuse publishing, cloud, and package credentials for further compromise; removing an injected workflow does not revoke stolen tokens or undo packages, images, or deployments created during the breach. GitGuardian reported 772 affected repositories during a prior window and OpenSourceMalware recovered 717-790 through October 9. A mass injection on October 8 modified 346 repositories across two compromised maintainer accounts, including active and decade-dormant projects.
Two newly registered lookalike domains, my-gitlab.com (2026-09-22) and my-github.com (2026-10-09), point to a likely next phase of developer-facing deception: my-github.com resolves to the active GhostAction collector IP and supports wildcard DNS, while gitlab.my-gitlab.com hosts an apparent GitLab service on AWS. Different registrars, ASNs, and DNS designs mean common ownership isn’t proven, but the names and services justify immediate monitoring for phishing, OAuth/PAT theft, malicious clone URLs, poisoned packages, and runner registration. The collector IP is also used for broad scanning and probing and is allocated in RIPE to Vigilant Cyber SAS; recommended hunting should include DNS/proxy/browser/email logs, git remotes and workflow files, OAuth redirects and token prompts, and outbound CI/runner connections.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.