Software supply chain trapped: GitHub Actions attack from March 2025
A developer audited a multi-surface software supply chain, revealing how a single compromised GitHub Action infects hundreds of dependent repositories.
The March 2025 attack on tj-actions enabled malware injection into CI/CD pipelines across 6 different surfaces (git, PyPI, npm, Maven, etc.).
The incident exposes fragility of modern supply chains, where a single transitive dependency can become critical infection vector at entire ecosystem scale.