Back to advisories

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

The GhostAction campaign is actively compromising GitHub maintainer accounts and injecting malicious workflows into thousands of repositories to steal API keys, tokens, and other secrets. If your organization uses dependencies from affected open-source projects, those workflows could exfiltrate your credentials. Hundreds of repos are already compromised with thousands of users at risk.

CRITICALAdvisoryOct 10, 2026
Action required
Immediately audit GitHub Actions workflows in your repositories and CI/CD pipelines for suspicious audit or security check jobs. Block outbound connections to 185.220.101.45 and scan logs for any exfiltration. Review GitHub Actions audit logs for unexpected workflow modifications and revoke any exposed API keys or tokens.
Affected products
GitHub ActionspyxelathenadriverDevOpsGPT