GitHub Supply Chain Attack sees thousands of tokens and secrets stolen in the ghostaction -campaign


  • Ghostaction Attack stole 3,325 secrets from 327 GitHub accounts
  • Gitguardian helped shut it down and warned affected projects
  • A separate NPM attack hit 2,000 accounts but was not related

Thousands of secrets such as Pypi and AWS KEYS, GitHub tokens and more were recently stolen during a supply chain attack against GitHub, called ‘Ghostaction’. The attack was discovered by security scientists Gitguardian, who informed GitHub and got it closed.

Gitguardian’s researchers first discovered the attack when they were notified of a GitHub project called FastUid, which was compromised. The project’s maintenance account was evidently divided and used to publish a malicious action work called “Add Github Actions Security Workflow”.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top