The github supply chain attack sees thousands of tokens and stolen secrets in the Ghostaction campaign




  • Ghostacion Attack stole 3,325 secrets of 327 github accounts
  • Gitguardian helped close it and alerted the affected projects
  • A separate NPM attack reached 2,000 accounts but was not related

Thousands of secrets such as Pypi and Aws Keys, Tokens Github and more were recently stolen during a supply chain attack against Github, called ‘Ghostacion’. The attack was seen by Gitguardian security researchers, who notified Github and closed it.

Gitguardian researchers saw the attack for the first time when they were notified of a github project called Farstuid committed. The project’s maintenance account was evidently divided and used to publish a work actions of malicious actions called “Add GITHUB SAFETY SAFETY FLOW”.

Leave a Comment

Your email address will not be published. Required fields are marked *