36-Month Precision Supply Chain Campaign Targeting DevSecOps Infrastructure (CVE-2024-3094, CVE-2025-30066, CVE-2025-30154) — Threadlinqs Intelligence
As of 2026-05-30, 36-Month Precision Supply Chain Campaign Targeting DevSecOps Infrastructure (CVE-2024-3094, CVE-2025-30066, CVE-2025-30154) is a critical-severity supply chain threat attributed to JiaT75 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0310 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: JiaT75 · China · ESPIONAGE
A systematic 36-month supply chain attack campaign (2024-2026) targeting DevSecOps tools including XZ Utils (CVE-2024-3094, CVSS 10.0), tj-actions/changed-files (CVE-2025-30066), reviewdog
This threat profile documents a coordinated multi-year supply chain campaign spanning from October 2021 to March 2026, systematically targeting DevSecOps infrastructure — the very tools defenders rely on to secure their software supply chains.
The campaign exhibits a striking "March pattern" with major incidents clustering in Q1: XZ Utils discovery on March 28, 2024; tj-actions/reviewdog compromise on March 14, 2025; and Trivy/litellm incidents within a 5-day window on March 19-24, 2026. This temporal clustering exploits peak Q1 release cycle pressure, maintainer conference travel (RSA, KubeCon EU), and elevated enterprise deployment rates.
CASE STUDY 1 — XZ UTILS BACKDOOR (CVE-2024-3094, CVSS 10.0):
The most sophisticated incident began in October 2021 when threat actor "JiaT75" (Jia Tan) created a GitHub account and began contributing to the XZ Utils project. Over 30+ months, the actor built legitimate credibility through quality contributions. Coordinated pressure from sock puppet accounts "Jigar Kumar" and "Hans Jansen" accelerated the maintainer's willingness to grant commit access in January 2023. In February 2024, the actor injected a backdoor via binary test files (tests/files/bad-3-corrupt_lzma2.xz, tests/files/good-large_compressed.lzma) that used tr utility de-obfuscation to extract a precompiled object file during the liblzma build process. The payload hooked RSA_public_decrypt to compromise SSH authentication on x86_64 systems with systemd. The backdoor was discovered on March 28, 2024 by Microsoft engineer Andres Freund through SSH performance anomalies. Affected versions: XZ Utils 5.6.0 and 5.6.1.
CASE STUDY 2 — TJ-ACTIONS/REVIEWDOG (CVE-2025-30066, CVE-2025-30154):
On March 11, 2025, the reviewdog/action-setup GitHub Action was compromised when attacker "hackerbot-claw" exploited GitHub's automated team invitation system based on activity thresholds, receiving write access to the @reviewdog/actions-maintainer team. The attacker pushed malicious commits and redirected the v1 tag, creating a transitive dependency chain: reviewdog/action-setup → reviewdog/action-typos → tj-actions/eslint-changed-files → tj-actions/changed-files. On March 14-15, 2025, tj-actions/changed-files tags v1 through v45.0.7 were pointed to malicious commit 0e58ed8. The payload executed a Python script performing /proc/{PID}/mem memory scraping of Runner.Worker, Runner.Listener, runsvc, and run.sh processes to extract GitHub Actions secret JSON structures. Secrets were exfiltrated via public CI workflow logs, bypassing GitHub's log masking layer which operates at a different abstraction level. Over 23,000 repositories were affected. Both CVEs were added to CISA's Known Exploited Vulnerabilities catalog.
CASE STUDY 3 — TRIVY/AQUA SECURITY GITHUB ACTIONS (MARCH 2026):
This attack proceeded in three waves. Wave 1 (late February 2026): The attacker exploited a pull_request_target workflow vulnerability in Aqua Security's GitHub Actions, executing base branch workflows with full secret scope to extract a privileged Personal Access Token. Wave 2 (March 1-19, 2026): After public disclosure, Aqua Security performed credential rotation but critically overlooked the aqua-bot service account token, which retained release-signing permissions, providing 18 days of undetected residual access. Wave 3 (March 19, 2026, 17:43 UTC): The attacker force-pushed 76 of 77 trivy-action version tags and all 7 setup-trivy tags to malicious commit e0198fd2b6e1679e36d32933941182d9afa82f6f (unreachable from master). Simultaneously, trivy v0.69.4 was published through compromised release automation. The malicious entrypoint.sh grew from 2,855 bytes to 17,592 bytes (6.16x increase), containing a 105-line credential sweep block that executed before the legitimate scanner. On GitHub-hosted runners, it performed process memory scraping identical to the tj-actions technique. On self-hosted runners, it conducted broad filesystem sweeps targeting SSH keys, AWS/GCP/Azure cre
Target sectors: technology, government, financial, healthcare, defense, cloud-infrastructure, devops, cybersecurity
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, CVE-2024-3094, CVE-2025-30066, CVE-2025-30154, T1195, T1195, T1199, T1059, T1554, T1546, T1543, T1098, T1611, T1027