logo

GhostAction campaign (Campaign)

ID: c7700532-11d3-59c3-b1b5-ccd2023e0a6f

STIX ID: report--c7700532-11d3-59c3-b1b5-ccd2023e0a6f

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2025-09-05

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

GitGuardian reported the 'GhostAction' campaign where attackers who obtained write access to repositories added malicious GitHub Actions workflows (commonly named "Github Actions Security") that exfiltrate CI/CD secrets via HTTP POST to an attacker-controlled endpoint (bold-dhawan.45-139-104-115.plesk.page / 45.139.104.115). The campaign affected 327 users, 817 repositories, and 3,325 secrets (npm, PyPI, Docker Hub, GitHub tokens, cloud keys); stolen tokens enable trojaned package/image publishes and cloud keys allow pivoting, persistence, and potential escalation until workflows are removed and secrets rotated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.