Skip to content
Brief Security & Trust ·

Fake security workflow hits 345 GitHub repos via two hijacked maintainer accounts

StepSecurity says the GhostAction campaign hit repositories tied to pyxel and Uber's athenadriver, and confirmed data reached the attacker from athenadriver.

In brief
  • Attackers used two hijacked maintainer accounts to add a data-stealing job to 345 repositories on October 8. Rotating current secrets is not enough, because the job also reads old commits.

StepSecurity said attackers took over two maintainer accounts on October 8, 2026 and added a fake automated job to 345 repositories. The Takashi Kitao account (pyxel game engine) pushed to 27 from 13:20 UTC. The Henry Wu account (Uber's athenadriver) pushed to 318 between 21:10 and 21:26 UTC. The job, named Security Audit or Github Actions Security, sends stored secrets and keys found in the code and old commits to a fixed IP address. The Hacker News said Socket sees a wider spread since October 7: tens of thousands of repositories, from over 500 accounts.

StepSecurity's logs show the attacker's server acknowledged data from uber/athenadriver. For pyxel, the job ran five times and succeeded, but receipt of data is not confirmed. In the athenadriver run, the job's own token was read-only, so harm depends on stolen secrets such as publishing keys. No harmful releases have used them so far, which does not make them safe. How the accounts were taken is unconfirmed; a leaked access token is the likeliest route.

Rotating today's secrets no longer ends a breach, because the job reads every old commit and sends data to a bare IP, with no domain lookup to filter. One approval setting stopped the theft in one repository. Ask: who has write access, do workflow runs need approval, where can runners connect, and where do AI keys live?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: StepSecurity.