{
  "id": 12848500,
  "title": "Malicious GitHub workflows expose credentials across hundreds of repositories",
  "url": "https://urgent.news/2026/10/08/malicious-github-workflows-expose-credentials-across-hundreds-of",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T09:36:31.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/malicious-github-workflows-expose-credentials-across-hundreds-of-repositories/"
  },
  "original_language": "en",
  "account": "Hackers infiltrated hundreds of GitHub repositories by deploying malicious automation workflows, intended to pilfer SSH keys, cloud credentials and access tokens. Researchers from GitGuardian disclosed that 772 public repositories, belonging to 373 users and organizations, were targeted during an attack campaign that lasted from August 31 to September 30. Of the 2,577 secrets the hackers aimed to steal, the majority of attempted intrusions did not result in confirmed credential exposure. The researchers, Gaetan Ferry and Guillaume Valadon, detailed this as a new phase of the GhostAction supply chain campaign, which leverages compromised developer credentials to insert unauthorized instructions into GitHub Actions, GitHub's automated software development system. Out of 3,669 workflow runs, only 499 executed in 32 repositories, with 336 successfully culminating in the exfiltration of 26 secrets. GitHub's security measures mitigated most malicious workflows, limiting the observed impact. However, researchers found that malicious workflows persisted in numerous repositories, posing a continued risk of credential exposure. The attackers disguised their commands as security maintenance operations. A malicious file, called githubactionssecurity.yml, included a commit message stating the addition of a GitHub Actions security workflow. Instead of indiscriminately harvesting all environment variables, the attackers examined existing repository setups to pinpoint specific credential names. Their injected workflows then attempted to extract those values and transmit them via HTTP requests to infrastructure under their control. A second variant, identified on September 7 across seven repositories, masqueraded as a routine security check, named security-check.yml. Its communication mechanism used identifiers that allowed attackers to link stolen credentials with individual repository breaches. The largest targeted categories were SSH private keys and deployment server credentials, with 446 entries each. Other targeted credentials included Azure credentials (218), container registry credentials (142), database credentials (112), and AWS access keys (106), along with FTP credentials (92), Google Cloud and Firebase credentials (80), and GitHub tokens (66). Additional targets encompassed authentication information for messaging services, software package registries, and artificial intelligence providers. GitGuardian noted that while the 2,577 targeted entries did not signify confirmed thefts, some identified values, including hostnames and usernames, were sensitive and could aid further attacks. The campaign unfolded in several concentrated waves, including 143 affected repositories on August 31, about 400 between September 2 and September 5, and another 103 on September 15. Evidence of remediation was limited; by October 5, only 124 affected repositories, representing roughly 16 percent of the total, had been effectively cleaned from the public development history scrutinized by the researchers. The researchers also discovered 92 instances where attackers modified existing malicious workflows, updating their communication destinations instead of introducing new files. This suggests that some repositories remained vulnerable across subsequent attack waves, enabling compromised automation instructions to persist undetected. Additionally, GitGuardian identified suspicious cryptocurrency mining activity linked to the DevOpsGPT open-source project. A malicious modification introduced mining software into the project's Docker configuration before the GhostAction workflows targeted repositories associated with the same organization. The maintainers of the project removed the malicious workflows on September 18 and reversed the cryptocurrency mining alteration on October 4. Researchers cautioned against assuming that both intrusions were orchestrated by the same attacker, as the technical characteristics of the incidents differed. While the incidents involved a shared compromised account, the distinct technical features left the attribution of the mining operation unresolved. GitHub's security documentation recommends repository administrators to restrict workflow permissions, conduct audits of credential handling, and rotate exposed secrets. Compromised authentication tokens should also be revoked, as removing malicious workflow files alone does not prevent attackers from regaining access through stolen credentials. The investigation identified 13 repositories affected by separate cryptocurrency mining operations involving at least four distinct campaigns. The researchers observed that mining activity sometimes preceded and sometimes followed credential theft attempts, indicating that compromised accounts could be exploited independently by different operators. The article Malicious GitHub workflows expose credentials across hundreds of repositories first appeared on Arabian Post.",
  "summary": "Hackers have compromised hundreds of GitHub repositories by inserting malicious automation workflows designed to steal SSH keys, cloud credentials and access tokens, with security researchers confirming the theft of 26 secrets from 13 repositories. Cybersecurity company GitGuardian identified 772 affected public repositories belonging to 373 users and organisations during an attack campaign…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}