A supply-chain campaign that hijacks developers' own accounts to plant credential-stealing workflows in GitHub repositories has surged again, with researchers now counting more than 500 compromised accounts and tens of thousands of affected repositories.

The activity, attributed to a campaign known as GhostAction, works like this: attackers obtain a maintainer's GitHub credentials — often a personal access token lifted from infostealer logs — then push a malicious workflow, usually named security-audit.yml or github_actions_security.yml, into the repository under the victim's own name.

StepSecurity reported that an account belonging to Takashi Kitao, author of the 18,400-star game engine pyxel, was used to push the workflow to 27 repositories; hours later the account of Henry Woo, original author of Uber's athenadriver, pushed it to 318 repositories in a 16-minute window. Socket said it has identified more than 500 accounts that committed the workflow to tens of thousands of repositories since October 7.

The payload runs on workflow_dispatch and any push, checks out the full git history and scans for 13 credential patterns — AWS keys, GitHub and GitLab tokens, and Anthropic, OpenAI and OpenRouter API keys — then ships them to an attacker-controlled IP address over plain HTTP. GitGuardian and Socket both warn that forks inherit the workflow, and that private forks are the most exposed because that is where committed secrets actually live.

The advice from researchers is blunt: assume compromise if you find the workflow, rotate credentials and delete it from every branch. The campaign's scale, and the fact that it turns a maintainer's own identity into the delivery mechanism, make it a pointed reminder that the CI/CD pipeline — not just the dependency list — is now a primary target.