[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feACvhPdfMim1LsmxyA8Hk2WQsOp-Xj-peiyTtF_fNpw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"5e9102dd-b5f9-4563-bf9f-587782f97623","ghostaction-campaign-hijacks-github-maintainer-accounts-to-steal-cloud-credentials-at-scale","b10fb6b0-c30e-4646-a851-94d27d4cf88a","GhostAction Campaign Hijacks GitHub Maintainer Accounts to Steal Cloud Credentials at Scale","Attackers compromised legitimate GitHub maintainer accounts to inject malicious CI\u002FCD workflows into hundreds of repositories, demonstrating how trusted identities can become the entry point for large-scale supply chain attacks. Beyond stealing GitHub Actions secrets, the campaign scanned full Git histories for cloud and AI service credentials — a critical reminder that secrets committed even briefly to version control history remain a persistent liability. This matters because exposed cloud credentials can grant attackers persistent, wide-ranging access to production infrastructure far beyond the compromised repository itself. Organizations that treat CI\u002FCD pipelines as inherently trusted environments without credential hygiene controls are disproportionately exposed to this class of threat.","**Immediate actions:**\n- Audit all GitHub maintainer accounts for unauthorized OAuth app authorizations, active sessions, and recent workflow file changes.\n- Rotate all secrets stored in GitHub Actions environments, repository settings, and any credentials that may have ever been committed to Git history.\n- Scan full repository Git histories using tools like `git-secrets`, `truffleHog`, or `gitleaks` to identify and revoke any exposed credentials.\n\n**Long-term improvements:**\n- Enforce phishing-resistant MFA (e.g., hardware security keys) on all accounts with repository write or admin access.\n- Store cloud credentials exclusively in dedicated secrets managers (e.g., AWS Secrets Manager, HashiCorp Vault) and inject them into pipelines at runtime rather than storing them as static repository secrets.\n- Implement branch protection rules and required code reviews for all changes to workflow files under `.github\u002Fworkflows\u002F`.\n\n**Detection measures:**\n- Configure alerting on unexpected additions or modifications to GitHub Actions workflow files, especially from accounts that do not typically modify CI\u002FCD configuration.\n- Monitor outbound network connections from CI\u002FCD runners for traffic to unknown or hardcoded IP addresses.\n- Enable GitHub's secret scanning and push protection features to automatically block and alert on credential exposure in commits.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 5: Account Management","CIS Control 12: Network Infrastructure Management","CIS Control 16: Application Software Security","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 IA-5: Authenticator Management","NIST SP 800-53 SA-12: Supply Chain Protection","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","NIST SP 800-218 SSDF PW.4: Reuse Existing, Well-Secured Software","SLSA Supply Chain Levels for Software Artifacts (Level 2+: Hosted source\u002Fbuild)","GDPR Article 32: Security of Processing (for EU-exposed repositories)","ITIL Change Management: Controlled change approval for pipeline configuration","published","2026-10-09T14:21:15.722889+00:00","2026-10-09T14:21:15.572+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fghostaction-cloud-credentials?utm_medium=feed","new-ghostaction-wave-hits-hundreds-of-repos-expanding-beyond-ci-cd-secrets-to-cl-63e4c5","New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI\u002FCD Secrets to Cloud Credentials",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]