Security Questions In Open Source Software Leaving Businesses Awhile Authorized Systems


  • A popular tool for automated software updates was compromised via GitHub
  • A piece of malicious code was added, which exposed user secrets
  • Dozens of organizations were already injured, researchers said

Tens of thousands of organizations, from SMBS to large companies, were at risk of accidentally postponing internal secrets after a supply chain attack hit a GitHub account.

A threat actor compromised the GitHub report on the (s) that maintained TJ-Actions/Changed Files, a tool that is part of a larger collection called TJ-Actions that helps automate software updates and is reportedly used by more than 23,000 organizations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top