step-security · Crawled Jul 22, 2026
Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization
1 Malware
Read original article ↗
AI Summary
Threat actors are increasingly targeting GitHub Actions secrets through campaigns like GhostAction and Megalodon, which exfiltrated thousands of secrets from public repositories. These attacks exploit the accumulation of unused, stale, or long-lived credentials that organizations fail to clean up. The Shai-Hulud worm exemplifies the risk, spreading by stealing npm tokens to publish malicious packages. Transitioning to OIDC-based authentication and eliminating unused secrets can reduce the attack surface significantly.
AI-extracted · verify before operational use
Extracted Entities 1 found
MITRE ATT&CK TTPs 19 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1071 Application Layer Protocol · Command And Control T1071.003 Mail Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1485 Data Destruction · Impact T1528 Steal Application Access Token · Credential Access T1530 Data from Cloud Storage · Collection T1552 Unsecured Credentials · Credential Access T1553 Subvert Trust Controls · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access