GhostAction campaign (Campaign)
ID: c7700532-11d3-59c3-b1b5-ccd2023e0a6f
STIX ID: report--c7700532-11d3-59c3-b1b5-ccd2023e0a6f
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-09-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
GitGuardian reported the 'GhostAction' campaign where attackers who obtained write access to repositories added malicious GitHub Actions workflows (commonly named "Github Actions Security") that exfiltrate CI/CD secrets via HTTP POST to an attacker-controlled endpoint (bold-dhawan.45-139-104-115.plesk.page / 45.139.104.115). The campaign affected 327 users, 817 repositories, and 3,325 secrets (npm, PyPI, Docker Hub, GitHub tokens, cloud keys); stolen tokens enable trojaned package/image publishes and cloud keys allow pivoting, persistence, and potential escalation until workflows are removed and secrets rotated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
