Home / Companies / Coralogix / Blog / Post Details
Content Deep Dive

GitHub Action Supply Chain Attack (CVE-2025-30066)

Blog post from Coralogix

Post Details
Company
Date Published
Author
Coralogix Team
Word Count
812
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 14, 2025, a critical supply chain attack targeted the popular GitHub Action tj-actions/changed-files, which is used by over 23,000 repositories, leading to the exposure of CI/CD pipeline secrets in logs. The attackers exploited a compromised GitHub personal access token to inject malicious code into the repository, which resulted in sensitive credentials being printed in public logs, putting public repositories at high risk. The incident, identified by StepSecurity’s Harden-Runner tool, prompted an immediate response from GitHub, including the temporary removal and restoration of the affected repository. The attack underscored the vulnerabilities in GitHub Actions security and highlighted the need for robust security measures such as pinning actions to commit hashes and using read-only secrets in workflows. Organizations were advised to audit logs, rotate secrets, and restrict permissions to mitigate potential risks. Coralogix's team found no compromise in their customer environments but recommended that customers perform their own validations to ensure security.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 10 1,233 139 73 +105%
Observability 1 1,867 328 114 +46%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.