GhostAction Supply Chain Campaign Uses Malicious GitHub Actions to Steal CI/CD Credentials
A new wave of the GhostAction supply chain campaign has compromised 772 public GitHub repositories, using fake GitHub Actions workflow files to steal credentials from CI/CD environments. The activity ran from August 31 through September 30, 2026, and targeted 2,577 secrets across 373 GitHub users...