troupe allegedly hacked as reported by BleepingComputer with details: A supply chain attempt on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially allowed threat actors to steal CI/CD secrets from GitHub Actions build logs.