GitHub Action tj-actions/changed-files supply chain attack: everything you need to know
ID: 617d24aa-d8d4-5a34-bfdd-ecd0340d439f
STIX ID: report--617d24aa-d8d4-5a34-bfdd-ecd0340d439f
Feed Name: Wiz Blog
Wiz Threat Research reports that the widely used GitHub Action tj-actions/changed-files was compromised prior to March 14, 2025, with malicious commits that caused CI runner memory to be dumped and secrets to be exposed (often as double-encoded base64) in workflow logs of affected repositories; dozens of public repos were observed with leaked credentials (AWS keys, GitHub PATs, npm tokens, private keys). The malicious gist hosting the script was removed and the repository reverted, but cached actions and already-exposed logs pose ongoing risk; the advisory provides detection and remediation steps (search for affected actions, inspect workflow runs for encoded payloads, rotate secrets, remove references, and pin actions to commit hashes) and notes tracking as CVE-2025-30066.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
