GitHub遭受级联式供应链攻击,CI/CD密钥泄露。
GitHub suffers a cascading supply chain attack compromising CI/CD secrets

原始链接: https://www.infoworld.com/article/3849245/github-suffers-a-cascading-supply-chain-attack-compromising-ci-cd-secrets.html

tj-actions 开发者此前曾表示无法确定攻击者是如何获得其 GitHub 个人访问令牌的。Wiz 的这一新发现提供了缺失的环节,表明 reviewdog 的最初泄露是这个级联攻击链中的第一环。除了已确认的 reviewdog/action-setup@v1 受损外,调查还发现该开发者其他几个可能受影响的 action。这些包括 reviewdog/action-shellcheck、reviewdog/action-composite-template、reviewdog/action-staticcheck、reviewdog/action-ast-grep 和 reviewdog/action-typos。这些工具受损的全部程度仍在调查中。虽然 GitHub 和 reviewdog 的维护者已实施了修复,但 Wiz 警告说,如果任何受损的 action 仍在使用中,针对“tj-actions/changed-files”的重复攻击仍然可能发生——尤其是在未轮换暴露的密钥时。

Hacker News 最新 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 GitHub遭受级联式供应链攻击,CI/CD密钥泄露 (infoworld.com) vinnyglennon 29分钟前 22分 | 隐藏 | 过去 | 收藏 | 2条评论 chuckadams 1分钟前 | 下一条 [–] 这次攻击被描述为“复杂”的,但我们应该感谢(GitHub)之星,这次数据泄露是一次马虎的工作,最终只让公共仓库受到了影响。这几乎就像一个灰帽黑客试图让供应链漏洞更明显,而没有造成实际损害。 回复 apimade 16分钟前 | 上一条 [–] 之前的讨论:https://news.ycombinator.com/item?id=43368870 回复 加入我们,参加6月16日至17日在旧金山举办的AI创业学校! 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请YC | 联系我们 搜索:

原文

The tj-actions developers had previously reported they could not determine exactly how attackers gained access to their GitHub personal access token. This new finding from Wiz provides the missing link, suggesting that the initial reviewdog compromise was the first domino in this cascading attack chain.

Beyond the confirmed compromise of reviewdog/action-setup@v1, the investigation has revealed several other potentially impacted actions from the same developer. These include reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos. The full extent of the compromise across these tools remains under investigation.

While GitHub and reviewdog maintainers have implemented fixes, Wiz warns that if any compromised actions remain in use, a repeat attack targeting “tj-actions/changed-files” could still occur — especially if exposed secrets are not rotated.

联系我们 contact @ memedata.com