zerofox logo
Advisories

ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity

Product Serial: F-2025-03-19a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on recent malicious cyber activity targeting GitHub repositories, Actions, and sensitive information associated with continuous integration (CI) and continuous delivery (CD) tools.

Standing Intelligence Requirements

DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • Since approximately March 14, 2025, GitHub repositories have been targeted in two likely separate malicious cyber campaigns, resulting in the likely compromise of user credentials, accounts, and sensitive information associated with continuous integration (CI) and continuous delivery (CD) tools.
  • At least 12,000 separate repositories have reportedly been targeted in a phishing campaign that leverages open authorization (OAuth) abuse to deceive users into granting attackers access to accounts and credentials.
  • The seemingly separate targeting of GitHub Actions via a supply chain compromise tracked by the National Institute of Standards and Technology (NIST) as CVE-2025-30066 was also first reported on March 14, 2025.
  • Subsequent research suggests that this initial incident may have facilitated the more recent targeting of the “tj-actions/changed-files” Action. As of the writing of this report the full extent of this activity is unclear, but there is a very likely chance that associated GitHub Actions remain compromised.

Tags: tlp:clear,  threat actor, vulnerability/exploit