Infoseccers at Google acquisition target Wiz think they've found the root cause of the GitHub supply chain attack that unfolded over the weekend, and they say that a separate attack may have been to blame. Just a year after Alphabet was said to be trying to buy the security shop for a claimed $23 billion, Google Cloud says it has signed a definitive agreement to acquire Wiz, Inc in an all-cash transaction for a cool $32 billion. The cloud security startup will become part of Google Cloud, with the tech giant saying the deal would "accelerate two large and growing trends in the AI era: improved cloud security and the ability to use multiple clouds." Previous talks around the mega-deal initially started positively but broke down after Wiz's leadership raised concerns about potential regulatory hurdles. The deal will be among the industry's largest of the year should it go through. Software engineer Tonye Jack, author of tj-actions/changed-files – the compromised GitHub Action that was recently seen leaking the CI/CD secrets of more than 23,000 projects – already said a stolen personal access token (PAT) was used to carry out the attack. How that token was acquired wasn't understood, however. But on Monday, Wiz said it followed up on a lead from researcher Adnan Khan, saying that reviewdog/action-setup, a different GitHub Action, was compromised on March 11 and could be the root cause of the stolen PAT at tj-actions. To recap and summarize: tj-actions/changed-files is a GitHub A...
Separate supply chain attack tied to 23K pwned GitHub repos
The Register
·Connor Jones
·Published Mar 18, 2025
·Updated
Affected Software
3 affected components
tj-actions changed-files
tj-actions eslint-changed-files
reviewdog action-setup
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a supply chain attack that affected approximately 23,000 GitHub repositories and explores the root cause identified by Wiz.
2
What security implications are discussed?
The security implications include the potential for malicious code injection from compromised GitHub actions affecting numerous projects.
3
What products or software are affected by this attack?
The affected software includes tj-actions changed-files, tj-actions eslint-changed-files, and reviewdog action-setup.
4
Who investigated the supply chain attack?
The investigation was conducted by security researchers at Wiz, a company recently acquired by Google.
5
What is the significance of this supply chain attack?
This attack highlights the vulnerabilities in software development ecosystems and the risks associated with third-party dependencies.