GhostAction 攻击向数万个 GitHub 仓库植入窃取凭证的 Actions workflow
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
AI 导读
StepSecurity 和 Socket 披露,GhostAction 供应链攻击活动通过两个高知名度开源维护者账号,向 340 多个仓库推送了恶意 GitHub Actions workflow。攻击者疑似利用信息窃取日志中泄露的 PAT 获取维护者账号,随后注入名为 security-audit.yml 或 github_actions_security.yml 的 workflow,通过 curl 以明文 HTTP 将数据外传到硬编码 IP 193.32.204[.]199。窃取内容包括仓库的 GitHub Actions secrets、CI/CD 凭证,以及工作树和完整 git 历史中的 AWS、Anthropic、OpenAI、OpenRouter API key 和 GitHub、GitLab token。