GhostAction Returns: Fake GitHub Workflows Steal API Keys

Security firms StepSecurity and Socket published analyses on October 9, 2026 of a new GhostAction wave. On October 8, two hijacked GitHub accounts pushed a fake "Security Audit" workflow into about 345 repositories. It steals secrets and keys, including AI service keys. It matters to anyone whose website code lives on GitHub.

What we know

  • Who is reporting it: StepSecurity and Socket, two companies that sell security tools for software development, in analyses dated October 9, 2026. Both are third-party research. Neither includes a response from GitHub.
  • What happened: on October 8, someone used the accounts of two well-known maintainers to add a GitHub Actions file, `security-audit.yml`, straight to the default branch of their repositories. It hit 27 repositories from one account, starting at 13:20 UTC, and 318 from the other, between 21:10 and 21:26 UTC, according to StepSecurity. They include the pyxel game engine and a repository owned by Uber.
  • How many: StepSecurity counts 345 repositories; Socket counts 346.
  • What the file does: it poses as a security audit and audits nothing. It sends the repository's GitHub Actions secrets to an attacker's server, along with any credentials it finds in the code and in the full git history. It looks for 13 patterns: AWS keys, Anthropic, OpenAI and OpenRouter keys, GitHub and GitLab tokens, and Google, Slack and SendGrid keys.
  • What is new: the history sweep. A key committed once and deleted the next day is still there and gets taken all the same, StepSecurity explains.
  • How they get in: with a maintainer's credential. StepSecurity considers a leaked personal access token the most plausible route. Socket says it did not observe how.
  • Scope: on October 9, a StepSecurity search returned 378 repositories with the file live on the default branch, forks excluded. Socket later added that it sees more than 500 accounts and tens of thousands of repositories since October 7. That is Socket's figure, and it gives no breakdown.
  • What has not happened: neither firm saw malicious package versions published with the stolen credentials. StepSecurity warns that this is not evidence the credentials are safe.
  • Background: the campaign dates from September 2025, when it stole more than 3,000 secrets from 817 repositories, according to StepSecurity.

What changes and what doesn't

The fix changes. Rotating the secrets configured in GitHub Actions used to be enough. With the history sweep, StepSecurity treats any credential that was ever in a commit as compromised, even if it was deleted.

The loot changes too: AI keys are now a first-class target. Socket explains why: they can be used to resell billable usage, and they open the data that flows through the key.

On scale, by this article's count from StepSecurity's figures: of the 378 repositories, 182 carry the history sweep (48%) and 88 send named secrets (23%).

The way in does not change. This is not a GitHub flaw: these are stolen accounts. And automatic protection is not enough. Since July 28, 2026, GitHub holds workflow runs it identifies as potentially malicious, but only on public repositories, according to its changelog. In this wave the file ran successfully on public repositories such as pyxel, according to StepSecurity. A business website's code usually sits in private repositories, which that hold does not cover.

How to tell if it affects you

It affects you if the code for your website, store or app is on GitHub, even in a private repository and even if a vendor manages it. Seven steps:

  1. Ask whoever builds your site: "Is our code on GitHub? Who has write access?" Every account with that access is a door.
  2. Open the `.github/workflows/` folder in each repository. StepSecurity names three files: `security-audit.yml`, `github_actions_security.yml` and `security-check.yml`. One that nobody on the team added is the red flag.
  3. Check the "Actions" tab. A completed run of "Security Audit" or "Github Actions Security" since August 31, 2026 should be treated as confirmed theft, according to StepSecurity.
  4. If it is there, rotate everything: Actions secrets and any credential that was ever in the repository. Start with what costs money or publishes in your name: AI, cloud and email-sending keys. The order is this article's recommendation.
  5. Revoke the token or session of the account that made the commit and delete the file from every branch, not just the default one. Rotating secrets is not enough while the way in stays open.
  6. Review usage on your AI keys in the provider's dashboard and set a spending limit if it offers one. This is this article's own precaution.
  7. To prevent it, StepSecurity recommends requiring approval for workflow runs and putting changes to `.github/workflows/` through review. It saw that approval gate stop the theft in one repository.

The exact searches for checking a whole organization are in the StepSecurity analysis.

Related: Google Ad Showing bing.com Leads to a Fake Claude Installer

Sources

Updates: this note will be extended if GitHub comments on this wave or if a malicious version of an affected package appears.