logo

GitHub supply chain attack spills secrets from 23,000 projects

ID: dc2c5e08-3575-5f4c-8b50-dca5f1307980

STIX ID: report--dc2c5e08-3575-5f4c-8b50-dca5f1307980

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-03-17

Date Updated: 2026-04-26

Author: Connor Jones

...
...

StepSecurity and other researchers disclosed a supply-chain compromise of the GitHub Action tj-actions/changed-files that injected code to exfiltrate CI/CD secrets into build logs; the issue (CVE-2025-30066, CVSS 8.6) affects thousands of repositories, with researchers finding dozens of exposed credentials (AWS keys, PATs, npm tokens, private RSA keys). Maintainers are urged to audit repositories, rotate all potentially exposed secrets, remove or pin the Action to specific commit SHAs, and apply account security improvements after the bot account compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.