GitHub Action supply chain attack exposed secrets in 218 repos
ID: c5c6d023-84e0-5df2-99d0-7a49864f5aab
STIX ID: report--c5c6d023-84e0-5df2-99d0-7a49864f5aab
Feed Name: Bleeping Computer
Threat Score
A malicious commit on March 14, 2025 compromised the GitHub Action 'tj-actions/changed-files', causing CI/CD secrets to be dumped to workflow logs; Endor Labs observed 5,416 repositories referencing the action, 614 workflow runs during the exposure window, and 218 repositories that printed secrets (including GitHub install tokens as well as DockerHub, npm, and AWS credentials), creating a time-limited but serious risk of credential abuse and follow-on supply-chain attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
