Story perspectives
Major GitHub Attack Exposes Secrets in 23,000 Repositories
3/18/2025
38 9
1 of 1
Story summary
- A devastating supply chain attack has rocked the tj-actions/changed-files GitHub Action, compromising over 23,000 repositories and leaking sensitive secrets such as AWS keys and GitHub tokens. Discovered on March 14, 2025, the malicious code, labeled CVE-2025-30066, has prompted GitHub to remove the action and urgently advise users to audit their repositories and change any exposed secrets.
