tj-actions/changed-files with Falco Actions
ID: 7855d39b-3b48-5fdf-9f8b-782e4fe79f07
STIX ID: report--7855d39b-3b48-5fdf-9f8b-782e4fe79f07
Feed Name: Sysdig Blog
Threat Score
**Executive Summary:** The report details a supply-chain compromise of the GitHub Action tj-actions/changed-files (CVE-2025-30066) where an attacker used a stolen Personal Access Token to add a memdump.py payload that reads Runner.Worker memory to extract secrets; it shows how Falco Actions can be integrated into CI/CD workflows to detect memory-dumping activity, capture runtime artifacts, and produce analysis reports for investigation and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
