GhostAction Attack Escalates By Targeting GitHub Users
OpenSourceMalware has identified a new stage in the ongoing GhostAction supply-chain campaign, originally found by GitGuardian in 2025. This escalation uses two new domains targeting GitHub and GitLab, with attackers compromising GitHub accounts and injecting malicious Actions workflows to steal CI/CD secrets across every repository they can modify.