Drooid Logo
Back to today’s briefing

Story perspectives

Major GitHub Attack Exposes Secrets in 23,000 Repositories

3/18/2025

38 9

1 of 1

Story summary
  • A devastating supply chain attack has rocked the tj-actions/changed-files GitHub Action, compromising over 23,000 repositories and leaking sensitive secrets such as AWS keys and GitHub tokens. Discovered on March 14, 2025, the malicious code, labeled CVE-2025-30066, has prompted GitHub to remove the action and urgently advise users to audit their repositories and change any exposed secrets.