Tj-actions Supply Chain Attack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 9, 2025
Last Seen
December 9, 2025

Tj-actions Supply Chain Attack is a threat campaign that exploits GitHub-based CI/CD workflows by leveraging GitHub Personal Access Tokens (PATs) to reach cloud control planes, enabling code-to-cloud intrusions via compromised pipelines.

Overview

Tj-actions Supply Chain Attack is a threat campaign that exploits GitHub-based CI/CD workflows by leveraging GitHub Personal Access Tokens (PATs) to reach cloud control planes, enabling code-to-cloud intrusions via compromised pipelines. It underscores the fragility of software supply chains and the risk of direct cloud resource manipulation through credential leakage.

Related Threat Clusters

  • Exposed GitHub PATs Enable Cloud Environment Breaches

    Threat actors are exploiting exposed GitHub Personal Access Tokens (PATs) to gain unauthorized access to cloud environments. The Wiz Customer Incident Response Team reported that these compromised tokens allow attackers…

    2 articles · Updated December 10, 2025

Recent Intelligence Reports

  • Code to Cloud Attacks: Github PAT to Cloud Control Plane — Wiz · December 9, 2025

CVSS v3.1 Breakdown