GhostAction spreads malicious GitHub Actions to tens of thousands of repositories
GhostAction has escalated, with more than 500 GitHub accounts used to commit malicious workflows across tens of thousands of repositories since October 7, 2026. The workflows impersonate security audits and steal credentials, including secrets buried in a repository’s Git history. Researchers urge developers to check affected repositories and forks, remove the workflows, and rotate exposed credentials.
Source
👉@sysadminoff
https://4sysops.com/archives/ghostaction-spreads-malicious-github-actions-to-tens-of-thousands-of-repositories/
Post #20824
35
