Skip to content
payloadreport
Sunday, October 11, 2026Cybersecurity news without the noise79 reports
Cloud Security

GitHub CI/CD Secrets: Socket Reveals GhostAction Wave Stealing Cloud and AI Credentials

Socket research reveals a new GhostAction wave targeting hundreds of GitHub repositories, expanding theft from CI/CD secrets to broader cloud and AI credentials.

GitHub CI/CD Secrets: Socket Reveals GhostAction Wave Stealing Cloud and AI Credentials
Illustration: Payload Report

Key points

  • Socket published first-hand research on the new GhostAction campaign activity.
  • The attack targets hundreds of GitHub repositories for credential harvesting.
  • Threat actors now extract cloud and AI credentials alongside traditional secrets.

Security researchers at Socket published first-hand research detailing a new wave of attacks attributed to the GhostAction threat group. This campaign targets hundreds of GitHub repositories, significantly expanding the scope of stolen data beyond traditional continuous integration and deployment secrets.

According to Socket, the attackers are now actively harvesting cloud credentials and artificial intelligence keys from source code and git history. This shift indicates a broader strategy to access sensitive infrastructure directly, rather than limiting theft to automated build pipelines.

Context and background

The GhostAction group has previously been known for stealing secrets from CI/CD environments. This new wave represents an evolution in their tactics, moving towards more valuable and versatile credentials. By targeting cloud and AI keys, the attackers gain potential access to active services and data stores, increasing the severity of any successful breach.

Who is affected

Hundreds of GitHub repositories are currently identified as targets or victims of this specific wave. The research highlights that the risk is not limited to large enterprises but extends to any public or private repository containing exposed credentials. Developers who have accidentally committed secrets to git history are particularly vulnerable to this automated scraping.

What happens next

Socket’s publication serves as a warning to the developer community about the evolving nature of credential theft. Security teams must recognise that standard CI/CD secret scanning is no longer sufficient. The inclusion of cloud and AI credentials in the attack scope requires a more comprehensive approach to secret management and code auditing across all repositories.

What to do and how to stay safe: GhostAction

  • Audit your git history for accidentally committed cloud or AI credentials using specialised scanning tools.
  • Rotate any exposed API keys or access tokens immediately upon discovery of a potential leak.
  • Implement pre-commit hooks to prevent sensitive data from being added to your repository in the first place.
  • Review repository permissions to limit who can push code and access sensitive configuration files.

Step-by-step guide: Identity and Access Management Best Practices for Secure Cloud Infrastructure

General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What new types of data is GhostAction stealing?

According to Socket, the group is now stealing cloud credentials and AI keys in addition to CI/CD secrets.

How many repositories are targeted?

The research indicates that hundreds of GitHub repositories are being hit by this new wave of attacks.

Where are these credentials found?

Attackers are extracting credentials from both active source code and the historical commit logs in git.

Sources

  1. Socket
GhostActionSocketGitHubcredential theftcloud security

Related stories

Cloud Compliance Mistakes: Why Controls Fail and How to Fix Them

Compliance frameworks often ignore the dynamic nature of cloud infrastructure, causing static controls to miss transient risks that automated systems create.