logo

Threat Assessment: GitHub Actions Supply Chain Attack: The Compromise of tj-actions/changed-files

ID: 796951f0-a90a-5301-b8b6-45a47f230c1c

STIX ID: report--796951f0-a90a-5301-b8b6-45a47f230c1c

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-03-18

Date Updated: 2026-04-28

Author: Unit 42

...
...

**Unit 42 analyzed a March–April 2025 multi-stage GitHub Actions supply-chain attack in which attackers compromised reviewdog/action-setup and tj-actions/changed-files (used by ~23k repos) to print CI runner memory and exfiltrate secrets and PATs via malicious commits, fork abuse, and tag overrides; the campaign included a targeted effort against Coinbase/agentkit and resulted in widespread exposure of workflow credentials, with recommended mitigations including secret rotation, action pinning, reducing workflow permissions, and auditing workflow logs.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.