tj-actions/changed-files supply chain attack (Incident)
ID: ae5b8d54-2382-5d84-8098-b19e58e53471
STIX ID: report--ae5b8d54-2382-5d84-8098-b19e58e53471
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A supply-chain compromise of the GitHub Action tj-actions/changed-files (CVE-2025-30066) injected malicious code into CI workflows to harvest repository secrets by encoding them into workflow logs; the issue affected all versions, likely originated from a compromised reviewdog/action-setup dependency, the repo was taken down and cleaned, but cached Actions and prior secret exposures remain a risk, and no external exfiltration was observed at discovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
