logo

GitHub Action hack likely led to another in cascading supply chain attack

ID: 6f4a8184-f227-57ab-92ad-9179af38e322

STIX ID: report--6f4a8184-f227-57ab-92ad-9179af38e322

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-03-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A supply-chain compromise of the reviewdog/action-setup@v1 GitHub Action injected a base64-encoded payload into install.sh that wrote CI/CD secrets into workflow logs; researchers believe this led to theft of a tj-actions bot Personal Access Token and secret exposure affecting about 23,000 repositories. Affected projects are advised to remove the compromised actions, delete workflow logs, rotate secrets, pin Actions to commit hashes, and use allow-listing to prevent recurrence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.