NoticiasNews

GhostAction vuelve: flujos de GitHub Actions maliciosos roban credenciales en miles de repositoriosGhostAction Is Back: Malicious GitHub Actions Workflows Steal Credentials Across Thousands of Repositories

2026-10-10

Según The Hacker News (9 de octubre de 2026), la campaña de robo de credenciales conocida como GhostAction ha reaparecido. Socket reporta que más de 500 cuentas de GitHub han subido un workflow malicioso a decenas de miles de repositorios desde el 7 de octubre.

Qué ocurrió

Los atacantes comprometieron cuentas de mantenedores de código abierto, entre ellas la del autor del motor de juegos pyxel y la del autor original de athenadriver, y desde ellas empujaron el workflow a más de 340 repositorios. GitGuardian ya había documentado que entre el 31 de agosto y el 30 de septiembre el mismo patrón alcanzó 772 repositorios públicos y apuntó a 2.577 secretos.

Cómo funciona

  • El archivo se disfraza de herramienta de seguridad (security-audit.yml o github_actions_security.yml).
  • Se ejecuta con workflow_dispatch o con cualquier push, recorre el árbol de trabajo y todo el historial de git buscando 13 patrones de credenciales (AWS, claves de servicios de IA, GitHub, GitLab y otras nubes).
  • Envía lo recolectado por HTTP a una dirección IP fija, incluso los secretos que alguien borró hace tiempo pero siguen en el historial.

Qué hacer

Busque ambos nombres de archivo en todas las ramas y forks desde el 31 de agosto. Si aparecen, asuma compromiso: revoque la credencial de GitHub, rote todos los secretos expuestos, elimine el workflow y desactive Actions en forks afectados. Active además autenticación resistente a phishing y tokens de alcance mínimo.

Lección para las empresas

El eslabón débil fue la cuenta de una persona, no el código. Los secretos en repositorios, los accesos compartidos y las integraciones sin trazabilidad son riesgos reales para cualquier equipo de desarrollo.

En TEKFENIX desarrollamos software a medida con gestión de secretos y revisiones de acceso desde el diseño, y productos como Servigo365 y CumplimientoControl mantienen trazabilidad de quién hizo qué y cuándo, clave para investigar incidentes como este. Fuente: The Hacker News.

According to The Hacker News (October 9, 2026), the credential-theft campaign known as GhostAction has resurfaced. Socket reports that more than 500 GitHub accounts have committed a malicious workflow to tens of thousands of repositories since October 7.

What happened

Attackers compromised open-source maintainer accounts, including the author of the pyxel game engine and the original author of athenadriver, and used them to push the workflow to more than 340 repositories. GitGuardian had already documented that between August 31 and September 30 the same pattern reached 772 public repositories and targeted 2,577 secrets.

How it works

  • The file is disguised as security tooling (security-audit.yml or github_actions_security.yml).
  • It runs on workflow_dispatch or any push, scans the working tree and the full git history for 13 credential patterns (AWS, AI-service keys, GitHub, GitLab and other clouds).
  • It sends the loot over plain HTTP to a hard-coded IP address, including secrets that were deleted long ago but remain in history.

What to do

Search all branches and forks for both file names since August 31. If found, assume compromise: revoke the GitHub credential, rotate every exposed secret, delete the workflow and disable Actions on affected forks. Also enable phishing-resistant authentication and least-privilege tokens.

Lesson for businesses

The weak link was a person's account, not the code. Secrets in repositories, shared access and untracked integrations are real risks for any development team.

At TEKFENIX we build custom software with secret management and access reviews by design, and products such as Servigo365 and CumplimientoControl keep a trail of who did what and when, essential for investigating incidents like this one. Source: The Hacker News.

← Volver al blog← Back to blog