[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-rep-mv2agqg9":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"537e6c55-f26f-4a23-8311-0ce3dc8f5f19","Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories","credential-stealing-github-actions-workflows-planted-in-tens-of-thousands-of-rep-mv2agqg9","The GhostAction campaign is actively compromising GitHub maintainer accounts and injecting malicious workflows into thousands of repositories to steal API keys, tokens, and other secrets. If your organization uses dependencies from affected open-source projects, those workflows could exfiltrate your credentials. Hundreds of repos are already compromised with thousands of users at risk.","critical","advisory",[],[13,14,15,16],"GitHub Actions","pyxel","athenadriver","DevOpsGPT","Immediately audit GitHub Actions workflows in your repositories and CI\u002FCD pipelines for suspicious audit or security check jobs. Block outbound connections to 185.220.101.45 and scan logs for any exfiltration. Review GitHub Actions audit logs for unexpected workflow modifications and revoke any exposed API keys or tokens.",[19],"4326c493-c8bb-4f5f-a3a7-d05c50266334",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fcredential-stealing-github-actions.html","active","2026-10-12T11:06:05.369+00:00","2026-10-10T11:06:11.903502+00:00","2026-10-10T11:06:25.889055+00:00",[28],{"id":19,"title":6,"url":22}]