2026-10-11 16:38 UTC

The GhostAction supply-chain campaign escalates by registering lookalike domains my-github.com and my-gitlab.com that resolve to attacker infrastructure, enabling phishing, malicious clone URLs, token theft, and CI/CD secret collection — a shift from IP-based collectors to developer-familiar domains for credential harvesting and workflow injection.

state: corroboratedheat: mediumuncertainty: mediumnovelscott: highsupply-chain-security ci-cd-attacks typosquattingOpenSourceMalwareGitGuardianSocketStepSecurity

What is this?

GhostAction is a software supply-chain campaign first reported by GitGuardian on September 5, 2025, in which attackers with write access to GitHub repositories (initial access vector unknown) injected a malicious GitHub Actions workflow named "Github Actions Security" that exfiltrated 3,325 CI/CD secrets — including npm, PyPI, Docker Hub, GitHub tokens, and cloud credentials — from 327 users across 817 repositories. In October 2026 the campaign escalated by registering typosquatting domains my-github.com (2026-09-22) and my-gitlab.com that resolve to the same attacker infrastructure (IP 45.139.104.115, previously seen at bold-dhawan.45-139-104-115.plesk.page and carte-avantage.com), shifting from raw IP collectors to developer-familiar domains for credential harvesting and workflow injection. Multiple security vendors (GitGuardian, StepSecurity, Wiz, Socket, Cycode) track the campaign; the initial compromise vector remains unidentified.

Why it matters to Scott

GhostAction's typosquatting domains (my-github.com, my-gitlab.com) directly target the GitHub platform Scott builds on (work:project.github) and the OAuth/token infrastructure his projects depend on (dev:project.nango, ip:concept.capability-tokens, ip:concept.proxy-mediated-tokenisation); the campaign's shift to developer-familiar domains for CI/CD secret theft makes it a concrete test case for his Sovereign Software Assurance supply-chain controls (ip:framework.sovereign-software-assurance) and Agent Provenance Stack verification requirements (ip:framework.agent-provenance-stack).
ip:framework.sovereign-software-assuranceip:concept.cryptographic-trustip:framework.agent-provenance-stackip:concept.provenanceip:concept.capability-tokensip:concept.proxy-mediated-tokenisationip:concept.zero-trust-for-decisionsdev:project.nangowork:project.githubip:framework.siloosip:concept.agent-addressabilityip:concept.delegation-surfacework:project.cloudflarework:project.crazy-domainsradar:github-actions-oidc-audience-gapradar:subql-common-npm-compromiseradar:shai-hulud-actions-reenabledradar:blender-mcp-maintainer-compromiseradar:arrayref-crates-supply-chain-compromiseradar:coding-assistant-supply-chain-trustradar:provenance-gate-tool-gatewayradar:kenwea-signed-install-attestationsradar:shadcn-polinrider-malicious-prs
queries asked of Scott's wikis
  • supply-chain security for AI/ML package registries (npm PyPI) and token rotation
  • CI/CD workflow compromise impact on agent memory systems and RAG pipelines
  • secret management patterns for local inference and model sovereignty tooling
  • GitHub Actions runner hardening and OIDC short-lived credentials in AI dev workflows
  • typosquatting domain detection integrated into developer tooling and agent harnesses

Measured heat

now 0 pts/hpeak 10 pts/hcomments 0/hpeers p26momentum: steady2 platformsage 75h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-08 13:00⭐ origin echo-reconstructedGhostAction campaign escalates with two new typosquatting domains: my-gitlab.com (registered 2026-09-22) and my-github.com (registered 2026-
OpenSourceMalware.com (c0a15726-c5b1-4b0d-85e6-fe15553df9e2) on blog (echo) · attributed from hn.story.50028187
—
10-10 00:16first on hacker news · published · +35.3hGhostAction attack using GitHub and GitLab lookalike domains
6mile
—
10-10 00:16amplified on hacker news 👑hn.story.50028187
6mile
peak 5 · 0 comments · 83% of case engagement
10-11 11:28amplified on hacker newshn.story.50042042
throw0101a
peak 1 · 0 comments · 18% of case engagement
10-10 01:32our radar first saw it · +36.5hdiscovery anchor: hn.story.50028187—
10-10 02:24reached heat=high · +37.4h · via ledger——
pace: p45 vs 1243 stories at the 72h mark (now 75h old) — ahead of apowerb-open-agent-runtime (1.2x), behind agentic-flooding-public-services (0.9x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnGhostAction attack using GitHub and GitLab lookalike domains
Retrieved article excerpt

Open article · Retrieved 2026-10-10T01:44:16.138074+00:00

BLOG

# GhostAction Attack Escalates By Targeting GitHub Users

OSM has identified a new evolution of the GhostAction attack, which targets GitHub users via malicious CI workflow files and worm-like behaviour

By c0a15726-c5b1-4b0d-85e6-fe15553df9e2 · 2026-10-09T23:55:53.631Z

GhostAction Attack Escalates By Targeting GitHub Users

OpenSourceMalware has identified a new stage in the ongoing "GhostAction" malicious campaign that GitGuardian originally [identified](https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/) in 2025. This latest evolution appears to be an escalation and used two new domains targeting GitHub and GitLab.  
  
The GhostAction campaign is a continuing supply-chain campaign in which attackers compromise GitHub accounts and inject malicious Actions workflows across every repository those accounts can modify. Triggered by pushes or manual execution, the workflows steal CI/CD secrets—including package-publishing, cloud, GitHub, and AI-service credentials—and exfiltrate them to attacker-controlled infrastructure. Later variants expanded collection by scanning repository contents and complete git history, recovering credentials that developers believed had been deleted. GitGuardian (https://blog.gitguardian.com/ghostaction-github-actions-supply-chain-attack- returns/)

Earlier today [Socket](https://socket.dev/blog/ghostaction-cloud-credentials) and [StepSecurity](https://www.stepsecurity.io/blog/ghostaction-returns) subsequently traced a renewed, highly automated wave to compromised maintainers whose access exposed hundreds of repositories, including prominent projects and long-dormant codebases. Their findings show that GhostAction remains an active account-takeover and credential-theft operation: attackers enumerate all writable repositories, push workflows directly without review, trigger executions, and use stolen publishing or cloud secrets to enable further supply-chain compromise.

The established GhostAction payload reads specifically named GitHub Actions secrets and sends them to attacker infrastructure. The newer `.github/workflows/security-audit.yml` variant also searches the complete checkout and git history for credential-shaped strings, captures contextual lines surrounding AWS keys, and POSTs the combined results over unencrypted HTTP to `193.32.204[.]199/?c=monami`.

Responders must assume exposure of active Actions secrets and credentials previously committed and later deleted. Removing the workflow does not revoke stolen credentials, invalidate the GitHub token used to alter the repository, or address packages, images, releases, and deployments produced during the compromise.

## Early Warning: A Possible New Developer-Targeting Wave

Two newly registered, code-hosting-themed domains may signal the next phase of developer targeting. `my-gitlab[.]com` was registered on September 22, 2026, followed 17 days later by `my-github[.]com`. The domains share the exact `my-<major code-host>.com` construction and the parallel `<brand>.my-<brand>.com` form. `my-github[.]com` points directly to the active GhostAction collector IP; `gitlab.my-gitlab[.]com` hosts an apparent GitLab service on separate AWS infrastructure. Common ownership is not yet proven, but the naming, timing, and developer-facing services justify early monitoring for phishing, malicious clone URLs, token theft, CI configuration abuse, and payload delivery.

The infrastructure suggests a possible shift from conspicuous IP-address collectors toward domains designed to look familiar to developers:

```
my-gitlab.com          registered 2026-09-22
└── gitlab.my-gitlab.com

my-github.com          registered 2026-10-09
└── github.my-github.com
```

This pattern could support several attacks against developers: GitHub or GitLab credential phishing, OAuth or personal-access-token theft, malicious repository clone instructions, fake API endpoints, poisoned package or release downloads, runner registration, and CI/CD secret collection. These are forecast scenarios derived from the naming and exposed services; they have not all been observed.

`my-github[.]com` is the higher-confidence indicator because it resolves directly to `193.32.204[.]199`, the current GhostAction exfiltration and scanning host. It also has wildcard DNS, allowing whoever controls the domain to use convincing hostnames without publishing individual records. `my-gitlab[.]com` is a lower-confidence watchlist domain: its configured `gitlab.my-gitlab[.]com` hostname resolves to an AWS EC2 address in Hong Kong where passive Shodan data identifies GitLab and nginx on ports 80 and 443.

The pair is not technically attributed to one operator. They use different registrars, registrant records, Cloudflare nameserver pairs, IP addresses, ASNs, and DNS designs, and no shared certificate or account artifact has been recovered. Defenders should nevertheless hunt and monitor both domains now because waiting for confirmed victim telemetry would forfeit the value of the early warning.

Recommended monitoring:

- DNS, proxy, browser, email, and endpoint events containing either apex domain or any subdomain;
- Git remotes, package metadata, documentation, workflow files, and shell history referencing either domain;
- authentication pages, OAuth redirects, personal-access-token prompts, runner-registration instructions, and clone URLs using the domains;
- outbound connections from developer workstations, CI runners, build systems, and package-publishing hosts;
- future DNS, certificate, hosting, and repository changes that create a direct link between the two domains.

## Threat Overview

Attribute

Value

Threat

GhostAction

Type

CI/CD credential theft and software supply-chain intrusion

Platform

GitHub and GitHub Actions

Severity

Critical where workflows can access publishing, cloud, or deployment secrets

First documented

September 2025

Current endpoint

`193.32.204[.]199` over HTTP

Files

`github_actions_security.yml`, `security-check.yml`, `security-audit.yml`

Triggers

`push`, `workflow_dispatch`

## Discovery

OpenSourceMalware identified a malicious PyPI package `claudecord` and reached out to the maintainer directly. We worked with that maintainer to help them mitigate the malware that had compromised dozens of their repositories. During that engagement, we noticed that there were hundreds of GhostActions victims with a new GitHub Actions based payload. Version `0.3.2` of the `claudecord` PyPI package contains `.github/workflows/github_actions_security.yml`, which POSTs named deployment, npm, and PyPI secrets to `http://193.32.204[.]199`. Its SHA-256 is:

```
7fbd40446a82c77b23432c6ab73bd8595c98e90e4f4a473198b4d1256f3e8c4b
```

The claimed upstream, `kanavdhanda/claudeCord`, shows the initial implant in commit `a69f8c4`, followed two seconds later by `Trigger security scan`. Commit `dd08e03` added `.github/workflows/security-audit.yml` the next day. Commit `7e03c5a` later removed the remaining malicious workflow.

GitGuardian reported 772 affected repositories between August 31 and September 30. OpenSourceMalware can currently recover 717 through that cutoff and 790 through October 9. Repositories and commits may disappear after disclosure, while injections continued after GitGuardian’s window; the present dataset is therefore a reproducible public lower bound.

### October 8 Mass Injection

Socket and StepSecurity resolved the newest activity to two compressed sweeps:

UTC window

Compromised account

Repositories

Detail

13:20–13:44

`kitao`

27

`kitao/pyxel` received one add and two update commits

21:10–21:26

`henrywoo`

318

39 source repositories, 279 forks, plus `uber/athenadriver`

**Total**

**2 accounts**

**346**

Automated enumeration of writable repositories

The sweep included active projects and repositories dormant for roughly a decade, supporting automated enumeration rather than project selection. `kitao/pyxel` had approximately 18,420 stars at Socket’s collection time. The Uber-owned `uber/athenadriver` repository was reachable because its original author retained write access after the project moved under the Uber organization.

The `athenadriver` injection went directly to `master` without a pull request or review and used the legitimate maintainer identity as author and committer. StepSecurity reports that the commit was unsigned. Author identity therefore provides weak detection when a valid credential is abused; content, review state, burst timing, push path, and runner egress are stronger signals.

Socket observed successful executions and found the workflow still present on default branches it checked on October 9. It had not observed malicious PyPI or [crates.io](http://crates.io) releases attributable to this wave at publication time. That narrows observed impact but does not reduce the need to rotate publishing credentials.

## Infrastructure

Period

Endpoint

Reported repositories

September 2025

`bold-dhawan.45-139-104-115.plesk[.]page`

~900 total for the wave

September 2025

`carte-avantage[.]com`

Included above

September 2025

`objective-hopper.45-139-104-115.plesk[.]page`

Included above

Oct–Dec 2025; March 2026

`170.39.218[.]2`

~75

Nov 2025; March–April 2026

`*.oast.fun`

~250

Aug–Sept 2026

`193.32.204[.]199`

772 reported

September 2026

`193.32.204[.]199:3000/api/workflow/receive?inj=<id>`

7

October 2026

`193.32.204[.]199/?c=monami`

Unresolved

StepSecurity places the current IP in honeypot telemetry on September 4, 2026 and in an infected public repository on September 5. Those dates provide an earlier investigation boundary than the major public injection bursts.

### Infrastructure Reuse Beyond GhostAction

At OpenSourceMalware our years of incident response in software supply chain attack led us to look deeper at the indicators and behaviours of the GhostAction threat actor. In particular we like to go deep on the infrastructure used as it often is the best way to pivot into new, previously unknown, parts of the campaign.  
In this case, dedicated infrastructure research found that `193.32.204[.]199` is also being used as active malicious internet scanner. GreyNoise, Shodan, OTX, SCARD, SANS ISC, and [BlockList.de](http://BlockList.de) independently observed scanning, brute-force, web probing, or honeypot traffic. A SANS daily view recorded 11,286 probes to TCP/8080, while SCARD recorded 413 events dominated by suspicious web-scanner user agents. The threat actor, or actors, is clearly using this Ubuntu server to act both as a inbound exfiltration collection server, AND as a outbound scanner looking for vulnerabilities and exploitable misconfigurations.

It is *very* unusual to see infrastructure used in software supply chain attacks re-used in this way.

In a similar way, the legacy IP used in the first version of GhostAction identified by GitGuardian, `45.139.104[.]115` has 389 OTX passive-DNS records spanning a phishing-heavy neighborhood. Recurring themes include Ameli/Carte Vitale, government fines, parcel delivery, Netflix, banking, and SNCF. `carte-avantage[.]com` was independently reported as an SNCF payment-card phishing site before its 2025 GhostAction use. This establishes multi-purpose malicious use of the infrastructure but does not prove that one operator controlled every co-hosted domain.

#### Current IP ownership and exposure

RIPE RDAP assigns `193.32.204.0/24` to the object `vcyber`, with Vigilant Cyber SAS as the registered organization and `[email protected]` as the abuse contact. The prefix is currently announced by AS153622, Madina IT. Commercial geolocation sources variously place the address in Helsinki, Istanbul, or Turkey. These records describe allocation, routing, and database-derived location respectively; none establishes where the GhostAction operator resides.

Shodan InternetDB observed OpenSSH 8.9p1 on TCP/22, Apache 2.4.52 on TCP/80, and TCP/8900 as active on the IP address. URLScan independently reco
6mile50
🟧 echo.blog ⭐GhostAction campaign escalates with two new typosquatting domains: my-gitlab.com (registered 2026-09-22) and my-github.com (registered 2026-OpenSourceMalware.com (c0a15726-c5b1-4b0d-85e6-fe15553df9e2)——
🟧 hnEvaluating Whether GPT-6 Astra Performs Unsanctioned Supply-Chain Attacksthrow0101a10

Interpretation history

Decision trace