The attack on the Github supply chain sees thousands of tokens and secrets stolen in the Ghostaction campaign


  • Ghostaction Attack stolen 3,325 secrets of 327 GitHub accounts
  • Gitguardian helped arrest him and alerted affected projects
  • A separate NPM attack struck 2,000 accounts but was not linked

Thousands of secrets such as Pypi and AWS Keys, Github Tokens, and more, were stolen recently during a supply chain attack against Github, nicknamed “Ghostaction”. The attack was spotted by Gitguardian security researchers, who informed Github and made him close.

Gitguardian researchers first spotted the attack when they were informed of a Github project called Fastuuid Compromis. The project responsible for the project was obviously penetrated and used to publish a workflow of malicious actions called “Add Github Actions Security Workflow”.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top