Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

South African comic book fans gather at Comic-Con Africa in Johannesburg

August 30, 2025

Thousands of redheads celebrate their strands at Dutch festival

August 30, 2025

Saturday’s Powerball drawing worth $1 billion

August 29, 2025
Facebook X (Twitter) Instagram
Trending
  • South African comic book fans gather at Comic-Con Africa in Johannesburg
  • Thousands of redheads celebrate their strands at Dutch festival
  • Saturday’s Powerball drawing worth $1 billion
  • Pollution, development and climate change threaten Florida’s freshwater springs
  • With dawn of AI, talk of tech and religion merge for some
  • What is Labor Day. All you need to know
  • White House Reportedly Selects Jim O’Neill As CDC Director As Staffers Protest
  • Trump Administration Could Target Chicago With New Immigration Operation
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Sunday, August 31
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Popular GitHub Action Targeted in Supply Chain Attack
Cybersecurity

Popular GitHub Action Targeted in Supply Chain Attack

adminBy adminMarch 17, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 78


A popular GitHub Action has been compromised in a supply chain attack apparently targeting secrets associated with continuous integration and continuous delivery (CI/CD).

The targeted GitHub Action is called ‘tj-actions/changed-files’. Tj-actions provides GitHub Actions for streamlining CI/CD processes. Changed-files, which is actively used in over 23,000 repositories, is designed for tracking file and directory changes.

According to StepSecurity, a security company specializing in GitHub Actions, the incident started on March 14 and involved a threat actor modifying the Changed-files code to execute a malicious Python script designed to dump CI/CD secrets to build logs.

“If the workflow logs are publicly accessible (such as in public repositories), anyone could potentially read these logs and obtain exposed secrets,” StepSecurity said.

While the security firm has seen multiple public repositories leaking secrets in build logs that can be accessed by anyone, it noted that there is no evidence of the leaked secrets being exfiltrated. 

A majority of the existing Changed-files version tags were updated to refer to the malicious commit. The CVE identifier CVE-2025-30066 has been assigned to this incident. 

Software supply chain security firm Endor Labs has also tracked this incident and found no evidence that downstream open source libraries or containers have been impacted.

“The attacker was likely not looking for secrets in public repositories — they are already public. They were likely looking to compromise the software supply chain for other open source libraries, binaries, and artifacts created with this. Any public repository that creates packages or containers as part of a CI pipeline could have been impacted. That means potentially 1,000s of open source packages have the potential to have been compromised,” Endor said in a blog post.

Advertisement. Scroll to continue reading.

“This can also apply to enterprise organizations that have both private and public repositories. If these repositories share CI/CD pipeline secrets for artifact or container registries these registries can be potentially compromised,” the company added.

On March 15, GitHub removed the tj-actions/changed-files action and restored it on the same day after the malicious commit was removed from all tags and branches. 

Tj-actions developers and the security firms have shared recommendations on checking for indicators of compromise (IoCs) and incident response steps. 

There has been some speculation regarding this incident, with some believing that it may have been an attack conducted by an unsophisticated threat actor or that it was just an attempt to raise awareness of the potential risks.

One researcher pointed out that one year ago he published a blog post describing a theoretical attack scenario targeting tj-actions/changed-files.

Related: GitHub Actions Artifacts Leak Tokens and Expose Cloud Services and Repositories

Related: GitLoker Strikes Again: New “Goissue” Tool Targets GitHub Developers and Corporate Supply Chains

Related: North Korean Fake IT Workers Pose as Blockchain Developers on GitHub

Related: GitHub Launches Fund to Improve Open Source Project Security



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

OnlyFans Billionaire’s Fortune Doubles Amid Sale Talks And $700 Million Dividend

August 22, 2025

OnlyFans, a NSFW social network for creators has become a cash cow for its owner…

Tennis Legend Roger Federer Is Now A Billionaire

August 22, 2025

Sam Altman Is Going After Elon Musk’s Empire, One Company At A Time

August 18, 2025

How A Berkeley Professor Built Billion-Dollar Companies In His Lab

August 10, 2025
Our Picks

South African comic book fans gather at Comic-Con Africa in Johannesburg

August 30, 2025

Thousands of redheads celebrate their strands at Dutch festival

August 30, 2025

Saturday’s Powerball drawing worth $1 billion

August 29, 2025

Pollution, development and climate change threaten Florida’s freshwater springs

August 29, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.