According to the theory, the recent breach of “tj-actions/changed-files” that exposed CI/CD secrets was caused by a cascading supply chain attack that started with the penetration of the “reviewdog/action-setup@v1” GitHub Action.
A supply chain assault on the tj-actions/changed-files GitHub Action last week resulted in malicious code writing CI/CD secrets to 23,000 repositories’ workflow logs. The attacker may have stolen the secrets if those logs had been made public.
The creators of tj-actions are unable to determine the precise method by which the attackers gained access to a GitHub personal access token (PAT) that a bot used to make harmful code modifications.
Researchers at Wiz believe they may have discovered the solution today read more about GitHub Action hack likely led to another in cascading supply chain attack.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
