ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity
|by Alpha Team

ZeroFox Intelligence Flash Report - GitHub Repositories Targeted in Malicious Cyber Activity
Product Serial: F-2025-03-19a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on recent malicious cyber activity targeting GitHub repositories, Actions, and sensitive information associated with continuous integration (CI) and continuous delivery (CD) tools.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Since approximately March 14, 2025, GitHub repositories have been targeted in two likely separate malicious cyber campaigns, resulting in the likely compromise of user credentials, accounts, and sensitive information associated with continuous integration (CI) and continuous delivery (CD) tools.
- At least 12,000 separate repositories have reportedly been targeted in a phishing campaign that leverages open authorization (OAuth) abuse to deceive users into granting attackers access to accounts and credentials.
- The seemingly separate targeting of GitHub Actions via a supply chain compromise tracked by the National Institute of Standards and Technology (NIST) as CVE-2025-30066 was also first reported on March 14, 2025.
- Subsequent research suggests that this initial incident may have facilitated the more recent targeting of the “tj-actions/changed-files” Action. As of the writing of this report the full extent of this activity is unclear, but there is a very likely chance that associated GitHub Actions remain compromised.
Tags: tlp:clear, threat actor, vulnerability/exploit