B
今週中
GitHub Actionsのワークフローを悪用して認証情報を盗み出す大規模なサプライチェーン攻撃「GhostAction」
📌 一言でいうと
GitHub Actionsのワークフローを悪用して認証情報を盗み出す大規模なサプライチェーン攻撃「GhostAction」が確認されました。攻撃者は著名なオープンソースメンテナーのアカウントを侵害し、数万件のリポジトリに悪意のあるワークフローを仕込みました。これにより、PyPIなどのシークレット情報を含む3,300件以上の認証情報が流出したと報告されています。
🔍該当判定
- GitHub Actions(自動化機能)を自社プロジェクトで利用している
- GitHubで公開されているオープンソースライブラリを自社開発に取り入れている
- GitHubのリポジトリにAPIキーやパスワードなどの「Secrets」を保存している
- pyxel や athenadriver といったライブラリを社内で利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
GitHubリポジトリ内のワークフローファイル (.github/workflows/) に不審な変更がないか確認し、侵害が疑われる場合は直ちにシークレット(APIキー、トークン等)をローテートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】GitHub Actionsを標的としたサプライチェーン攻撃(GhostAction)について
お疲れさまです。GitHub Actionsを悪用した認証情報窃取キャンペーンに関する情報共有です。
■ 概要
「GhostAction」と呼ばれる攻撃者が、著名なメンテナーのアカウントを侵害し、数万件のリポジトリに悪意のあるGitHub Actionsワークフローを注入してシークレット情報を窃取しています。これにより、PyPI等の認証情報を含む3,300件以上のシークレットが流出したとされています。
■ 影響範囲
- GitHub Actionsを利用しているリポジトリ
- 侵害されたメンテナーが管理するオープンソースプロジェクトを利用している組織
■ 対応手順
1. 自社管理リポジトリの `.github/workflows/` 配下に、意図しない変更や不審なスクリプトが追加されていないか監査してください。
2. 外部ライブラリの更新履歴を確認し、不審なコミットがないかチェックしてください。
3. 万が一、不審なワークフローが検出された場合は、直ちに当該リポジトリに設定されているGitHub Secrets(APIキー、パスワード等)をすべて無効化し、再発行してください。
■ 参考情報
- StepSecurity / Socket 報告書
対応優先度: 高
対応期限: 速やかに
お疲れさまです。GitHub Actionsを悪用した認証情報窃取キャンペーンに関する情報共有です。
■ 概要
「GhostAction」と呼ばれる攻撃者が、著名なメンテナーのアカウントを侵害し、数万件のリポジトリに悪意のあるGitHub Actionsワークフローを注入してシークレット情報を窃取しています。これにより、PyPI等の認証情報を含む3,300件以上のシークレットが流出したとされています。
■ 影響範囲
- GitHub Actionsを利用しているリポジトリ
- 侵害されたメンテナーが管理するオープンソースプロジェクトを利用している組織
■ 対応手順
1. 自社管理リポジトリの `.github/workflows/` 配下に、意図しない変更や不審なスクリプトが追加されていないか監査してください。
2. 外部ライブラリの更新履歴を確認し、不審なコミットがないかチェックしてください。
3. 万が一、不審なワークフローが検出された場合は、直ちに当該リポジトリに設定されているGitHub Secrets(APIキー、パスワード等)をすべて無効化し、再発行してください。
■ 参考情報
- StepSecurity / Socket 報告書
対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] Supply Chain Attack via GitHub Actions (GhostAction)
Dear IT/Security Team,
We are sharing information regarding a large-scale credential-theft campaign targeting GitHub Actions workflows, attributed to 'GhostAction'.
■ Overview
Attackers have compromised high-profile open-source maintainer accounts to plant malicious workflows in tens of thousands of repositories. This activity has led to the exfiltration of over 3,300 secrets, including PyPI credentials.
■ Scope
- Repositories utilizing GitHub Actions
- Organizations relying on open-source projects managed by the compromised maintainers
■ Action Plan
1. Audit `.github/workflows/` directories in your repositories for unauthorized changes or suspicious scripts.
2. Review commit histories of external dependencies for any anomalous activity.
3. If suspicious workflows are found, immediately rotate all GitHub Secrets (API keys, tokens, etc.) associated with the affected repositories.
■ Reference
- Reports by StepSecurity and Socket
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a large-scale credential-theft campaign targeting GitHub Actions workflows, attributed to 'GhostAction'.
■ Overview
Attackers have compromised high-profile open-source maintainer accounts to plant malicious workflows in tens of thousands of repositories. This activity has led to the exfiltration of over 3,300 secrets, including PyPI credentials.
■ Scope
- Repositories utilizing GitHub Actions
- Organizations relying on open-source projects managed by the compromised maintainers
■ Action Plan
1. Audit `.github/workflows/` directories in your repositories for unauthorized changes or suspicious scripts.
2. Review commit histories of external dependencies for any anomalous activity.
3. If suspicious workflows are found, immediately rotate all GitHub Secrets (API keys, tokens, etc.) associated with the affected repositories.
■ Reference
- Reports by StepSecurity and Socket
Priority: High
Deadline: Immediate