The security problem in open source software leaves the companies concerned for systems


  • A popular tool for automated software updates has been compromised via Github
  • A piece of malicious code has been added, exposing user secrets
  • Dozens of organizations have already been injured, the researchers said

Tens of thousands of organizations, from SMEs to large companies, risked inadvertently exposing internal secrets after an attack on the supply chain struck a Github account.

A threat player compromised the GitHub account of the person (s) by keeping actions TJ / modified files, a tool that is part of a larger collection called TJ-action, which helps automate software updates and would have been used by more than 23,000 organizations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top