“The compromised Action prints CI/CD secrets in GitHub Actions build logs.”

An attacker repointed the version tags of tj-actions/changed-files, used by over 23,000 repos, to one malicious commit. Anyone pinned to a tag pulled it without changing a thing. The payload dumped secrets into build logs, which anyone can read on public repos. Pin actions to commit hashes.