
Impact, Root Cause of GitHub Actions Supply Chain Hack Revealed
- 21.03.2025 00:00
- securityweek.com
- Keywords: Supply Chain Attack
A supply chain attack on GitHub Actions was caused by a malicious script in the 'tj-actions/changed-files' action, which exposed CI/CD secrets. The root cause traced back to a compromised 'reviewdog/action-setup' action, affecting over 3,000 other actions and nearly 160,000 dependencies. Organizations should review their use of third-party actions to mitigate risks.