logo

tj-actions/changed-files with Falco Actions

ID: 7855d39b-3b48-5fdf-9f8b-782e4fe79f07

STIX ID: report--7855d39b-3b48-5fdf-9f8b-782e4fe79f07

Feed Name: Sysdig Blog

Threat Score
88/100

Date Published: 2025-04-10

Date Updated: 2026-05-01

...
...

**Executive Summary:** The report details a supply-chain compromise of the GitHub Action tj-actions/changed-files (CVE-2025-30066) where an attacker used a stolen Personal Access Token to add a memdump.py payload that reads Runner.Worker memory to extract secrets; it shows how Falco Actions can be integrated into CI/CD workflows to detect memory-dumping activity, capture runtime artifacts, and produce analysis reports for investigation and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.