logo

GitHub restores code following malicious changes to tj-actions tool

ID: e9257036-87bc-5bac-b42e-74643d1f09e3

STIX ID: report--e9257036-87bc-5bac-b42e-74643d1f09e3

Feed Name: The Record from Recorded Future News

Threat Score
80/100

Date Published: 2025-03-17

Date Updated: 2026-05-01

...
...

A widely used GitHub Action (tj-actions/changed-files) was maliciously modified in a supply-chain attack (CVE-2025-30066) to expose CI/CD secrets in build logs; GitHub intervened, maintainers restored the code, and organizations are urged to audit usages and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.