logo

GitHub Action supply chain attack exposed secrets in 218 repos

ID: c5c6d023-84e0-5df2-99d0-7a49864f5aab

STIX ID: report--c5c6d023-84e0-5df2-99d0-7a49864f5aab

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious commit on March 14, 2025 compromised the GitHub Action 'tj-actions/changed-files', causing CI/CD secrets to be dumped to workflow logs; Endor Labs observed 5,416 repositories referencing the action, 614 workflow runs during the exposure window, and 218 repositories that printed secrets (including GitHub install tokens as well as DockerHub, npm, and AWS credentials), creating a time-limited but serious risk of credential abuse and follow-on supply-chain attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.