logo

New GitHub Action supply chain attack: reviewdog/action-setup

ID: da218118-c7da-5854-8eaf-8552bfa3f19e

STIX ID: report--da218118-c7da-5854-8eaf-8552bfa3f19e

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2025-03-17

Date Updated: 2026-05-01

...
...

**Executive summary:** Wiz Research identified a chain of supply-chain compromises affecting reviewdog/action-setup@v1 and tj-actions/changed-files that injected base64-encoded malicious payloads into CI install scripts, causing workflow logs to expose repository secrets (publicly visible for public repos) and enabling attempts to compromise downstream repositories including a targeted attempt against Coinbase; the issue has been assigned CVE-2025-30154 and guidance for detection, rotation of secrets, and hardening (hash-pinning actions, allow-listing) is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.