What Happened?
• The compromised Action executes a Python script that dumps CI/CD secrets from the Runner Worker process.
• Multiple v35 tags were modified four hours ago, indicating a recent supply chain attack.
• The malicious behavior can be observed in StepSecurity Harden-Runner insights, showing the Action downloading and executing an unauthorized script.