GitHub restores code following malicious changes to tj-actions tool
ID: e9257036-87bc-5bac-b42e-74643d1f09e3
STIX ID: report--e9257036-87bc-5bac-b42e-74643d1f09e3
Feed Name: The Record from Recorded Future News
Threat Score
A widely used GitHub Action (tj-actions/changed-files) was maliciously modified in a supply-chain attack (CVE-2025-30066) to expose CI/CD secrets in build logs; GitHub intervened, maintainers restored the code, and organizations are urged to audit usages and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
