Supply-chain attack exposing credentials affects 23K users of tj-actions
tj-actions/changed-files, corrupted to run credential-stealing memory scraper.
https://arstechnica.com/information-technology/2025/03/supply-chain-attack-exposing-credentials-affects-23k-users-of-tj-actions/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social
tj-actions/changed-files, corrupted to run credential-stealing memory scraper.
https://arstechnica.com/information-technology/2025/03/supply-chain-attack-exposing-credentials-affects-23k-users-of-tj-actions/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social