GhostAction Hackers Compromise 500+ GitHub Accounts to Steal Cloud and AI API Credentials

A new GhostAction campaign has expanded to more than 500 compromised GitHub accounts and has injected malicious workflows into tens of thousands of repositories since October 7, 2026. Socket’s October 9 update describes a credential theft operation targeting GitHub Actions secrets, cloud credentials, and AI service API keys embedded in source code and repository history. […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: