GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials

A new wave of the GhostAction supply chain campaign has compromised 772 public GitHub repositories, using fake GitHub Actions workflow files to steal credentials from CI/CD environments. The activity ran from August 31 through September 30, 2026, and targeted 2,577 secrets across 373 GitHub users and organizations, including cloud keys, SSH credentials, container registry logins, […]

This article has been indexed from Cyber Security News

Read the original article: