As cited
Copy frozen at (site build).
threat intel
New GitHub Action supply chain attack: reviewdog/action-setup
Wiz Research identified a supply chain attack on the reviewdog/action-setup GitHub Action that may have facilitated a separate compromise of the tj-actions/changed-files repository, which leaked secrets from affected repositories over the weekend. The attack demonstrates the risk of compromised GitHub Actions as a vector for broader supply chain compromise.
Why it matters: Development teams using these GitHub Actions are at risk of credential theft and lateral movement; practitioners should audit repositories using reviewdog/action-setup@v1 and tj-actions/changed-files for unauthorized access and rotate exposed secrets immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New GitHub Action supply chain attack: reviewdog/action-setup
Wiz Research identified a supply chain attack on the reviewdog/action-setup GitHub Action that may have facilitated a separate compromise of the tj-actions/changed-files repository, which leaked secrets from affected repositories over the weekend. The attack demonstrates the risk of compromised GitHub Actions as a vector for broader supply chain compromise.
Why it matters: Development teams using these GitHub Actions are at risk of credential theft and lateral movement; practitioners should audit repositories using reviewdog/action-setup@v1 and tj-actions/changed-files for unauthorized access and rotate exposed secrets immediately.
- Source published
- First seen by Cybersecurity Tracker