Supply Chain Attacks Targeting GitHub Actions Increased in 2025
ID: 44d1a98c-4d10-5393-9950-e984abf1f618
STIX ID: report--44d1a98c-4d10-5393-9950-e984abf1f618
Feed Name: Dark Reading
Threat Score
This report outlines a series of GitHub-focused software supply-chain attacks in which threat actors abused misconfigured GitHub Actions (for example tj-actions/changed-files, CVE-2025-30066) to steal secrets (access keys, PATs, npm tokens, private keys) and compromise downstream organizations—including an incident that affected Coinbase customers—highlighting active exploitation, the scale of impact, and the need for improved shared responsibility and defensive practices on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
