The GhostAction supply-chain campaign has evolved to use lookalike domains my-github.com and my-gitlab.com alongside continued GitHub account compromises that inject malicious Actions workflows to steal CI/CD secrets and credentials. The newly registered domains resolve to attacker infrastructure and may signal a shift toward phishing and developer targeting. Responders must assume exposure of active secrets and invalidate all potentially compromised credentials.