
Key points
- Socket published first-hand research on the new GhostAction campaign activity.
- The attack targets hundreds of GitHub repositories for credential harvesting.
- Threat actors now extract cloud and AI credentials alongside traditional secrets.
Security researchers at Socket published first-hand research detailing a new wave of attacks attributed to the GhostAction threat group. This campaign targets hundreds of GitHub repositories, significantly expanding the scope of stolen data beyond traditional continuous integration and deployment secrets.
According to Socket, the attackers are now actively harvesting cloud credentials and artificial intelligence keys from source code and git history. This shift indicates a broader strategy to access sensitive infrastructure directly, rather than limiting theft to automated build pipelines.
Context and background
The GhostAction group has previously been known for stealing secrets from CI/CD environments. This new wave represents an evolution in their tactics, moving towards more valuable and versatile credentials. By targeting cloud and AI keys, the attackers gain potential access to active services and data stores, increasing the severity of any successful breach.
Who is affected
Hundreds of GitHub repositories are currently identified as targets or victims of this specific wave. The research highlights that the risk is not limited to large enterprises but extends to any public or private repository containing exposed credentials. Developers who have accidentally committed secrets to git history are particularly vulnerable to this automated scraping.
What happens next
Socket’s publication serves as a warning to the developer community about the evolving nature of credential theft. Security teams must recognise that standard CI/CD secret scanning is no longer sufficient. The inclusion of cloud and AI credentials in the attack scope requires a more comprehensive approach to secret management and code auditing across all repositories.
What to do and how to stay safe: GhostAction
- Audit your git history for accidentally committed cloud or AI credentials using specialised scanning tools.
- Rotate any exposed API keys or access tokens immediately upon discovery of a potential leak.
- Implement pre-commit hooks to prevent sensitive data from being added to your repository in the first place.
- Review repository permissions to limit who can push code and access sensitive configuration files.
Step-by-step guide: Identity and Access Management Best Practices for Secure Cloud Infrastructure
General security guidance from the Payload Report newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What new types of data is GhostAction stealing?
According to Socket, the group is now stealing cloud credentials and AI keys in addition to CI/CD secrets.
How many repositories are targeted?
The research indicates that hundreds of GitHub repositories are being hit by this new wave of attacks.
Where are these credentials found?
Attackers are extracting credentials from both active source code and the historical commit logs in git.



