A popular tool for automated software updates was compromised via GitHub
A piece of malicious code was added, exposing user secrets
Dozens of organizations were harmed already, researchers said
Tens of thousands of organizations, from SMBs to large enterprises, were at risk of inadvertently exposing internal secrets after a supply-chain attack hit a GitHub account.
A threat actor compromised the GitHub account of the person(s) maintaining tj-actions/changed files, a tool that is part of a larger collection called tj-actions, which helps automate software updates, and is reportedly used by more than 23,000 organizations.
+ There are no comments
Add yours