GitHub supply chain attack spills secrets from 23,000 projects
ID: dc2c5e08-3575-5f4c-8b50-dca5f1307980
STIX ID: report--dc2c5e08-3575-5f4c-8b50-dca5f1307980
Feed Name: The Register (Security)
StepSecurity and other researchers disclosed a supply-chain compromise of the GitHub Action tj-actions/changed-files that injected code to exfiltrate CI/CD secrets into build logs; the issue (CVE-2025-30066, CVSS 8.6) affects thousands of repositories, with researchers finding dozens of exposed credentials (AWS keys, PATs, npm tokens, private RSA keys). Maintainers are urged to audit repositories, rotate all potentially exposed secrets, remove or pin the Action to specific commit SHAs, and apply account security improvements after the bot account compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
