logo

Supply Chain Security Risk: GitHub Action tj-actions/changed-files Compromised

ID: 929e3e72-34b4-51e1-b572-ac53233fa622

STIX ID: report--929e3e72-34b4-51e1-b572-ac53233fa622

Feed Name: Aqua Security Blog

Threat Score
88/100

Date Published: 2025-03-15

Date Updated: 2026-04-26

...
...

On 14–15 March 2025 a malicious commit to the widely-used GitHub Action tj-actions/changed-files (CVE-2025-30066) injected obfuscated code that executed a Python memdump to enumerate runner process memory and leak CI/CD secrets into GitHub Actions build logs; thousands of repositories may be impacted. The report includes the malicious commit hash, payload examples and memory dumps, guidance to identify impacted runs (double base64 decode of long outputs), and immediate mitigations: remove or pin the action to a safe SHA, rotate exposed secrets, audit runners, and adopt CI/CD supply-chain protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.