Threat Assessment: GitHub Actions Supply Chain Attack: The Compromise of tj-actions/changed-files
ID: 796951f0-a90a-5301-b8b6-45a47f230c1c
STIX ID: report--796951f0-a90a-5301-b8b6-45a47f230c1c
Feed Name: Palo Alto Networks Unit 42
**Unit 42 analyzed a March–April 2025 multi-stage GitHub Actions supply-chain attack in which attackers compromised reviewdog/action-setup and tj-actions/changed-files (used by ~23k repos) to print CI runner memory and exfiltrate secrets and PATs via malicious commits, fork abuse, and tag overrides; the campaign included a targeted effort against Coinbase/agentkit and resulted in widespread exposure of workflow credentials, with recommended mitigations including secret rotation, action pinning, reducing workflow permissions, and auditing workflow logs.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
