Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
ID: d9a97579-d42d-5529-b5fd-120bc39c1045
STIX ID: report--d9a97579-d42d-5529-b5fd-120bc39c1045
Feed Name: Bleeping Computer
Threat Score
**GhostAction supply-chain campaign:** GitGuardian discovered a widespread campaign where attackers used compromised maintainer accounts to add malicious GitHub Actions workflows that automatically exfiltrated CI secrets (PyPI, npm, DockerHub, GitHub tokens, Cloudflare, AWS keys, etc.) to an external endpoint; roughly 817 repositories were affected and an estimated 3,325 secrets stolen, putting multiple package ecosystems and SDKs at risk of trojanized releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
