The reviewdog action-setup Supply Chain Attack

Updated 5 Oct 2026 · Incident date 11 Mar 2025 · CI action

Packagereviewdog/action-setup@v1 (tag repointed 18:42-20:31 UTC on 2025-03-11); also affected action-shellcheck, action-staticcheck, action-ast-grep, action-typos, action-composite-template
Fileinstall.sh

The GitHub Action reviewdog/action-setup@v1 was compromised on 11 March 2025 between 18:42 and 20:31 UTC. During that window the v1 tag pointed to a malicious commit. Its install.sh script dumped CI secrets into the workflow logs.

The flaw has the id CVE-2025-30154. Wiz reports that it likely led to the compromise of tj-actions/changed-files.

What happened

An attacker moved the v1 tag of reviewdog/action-setup to a malicious commit for about two hours on 11 March 2025. Any workflow that ran the action in that window executed the bad code.

Wiz reports that the payload was base64 encoded and inserted directly into install.sh. It was not fetched from a remote server. The code dumped the CI runner memory that held workflow secrets, and it wrote them to the GitHub Actions log. In public repositories anyone can read those logs.

Wiz also describes the link to the tj-actions/changed-files incident. The action tj-actions/eslint-changed-files uses reviewdog/action-setup@v1. The tj-actions/changed-files workflow ran that dependency with a personal access token, which was then stolen. CISA lists both CVE-2025-30066 for tj-actions and CVE-2025-30154 for reviewdog.

The GitHub advisory rates it high, with a CVSS score of 8.6, and the weakness class is embedded malicious code (CWE-506).

Affected versions

The affected reference is reviewdog/action-setup@v1 as it stood from 18:42 to 20:31 UTC on 11 March 2025. Other reviewdog actions that depend on it are also affected.

The fix is in commit 3f401fe, according to the advisory. A workflow that did not run in the window did not run the bad code.

Indicators of compromise

The main sign is in the workflow log of the run.

How to check

Search your repositories for workflows that use the affected actions.

grep -rn "reviewdog/action-" .github/workflows

Then list the workflow runs from the window with the GitHub CLI and read their logs.

gh run list --created 2025-03-11 --limit 100

Open any run in that window and check the action-setup step for the double base64 strings.

What to do now

  1. Stop using the affected actions until you have updated them. Remove the references on all branches.
  2. Rotate every secret that a workflow run in the window could read.
  3. Download the workflow logs before they are deleted, so you keep the evidence.
  4. Update to the fixed version of reviewdog/action-setup and pin actions to a full commit hash.
  5. If you are in the US, you can report incidents to CISA at Report@cisa.gov.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here install.sh gained a decode-and-run step. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old reviewdog/action-setup@v1-prev --new reviewdog/action-setup@v1-current
files scanned: 77

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    install.sh
           It now runs a command on its own when it is installed, reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

What happened to reviewdog/action-setup?

On 11 March 2025 between 18:42 and 20:31 UTC the v1 tag pointed to a malicious commit whose install.sh dumped CI secrets into workflow logs. The CVE is CVE-2025-30154.

How do I check if my workflows used the compromised reviewdog action?

Search your workflows for reviewdog/action- references, then read the logs of runs from 11 March 2025 18:42 to 20:31 UTC. Look for double base64 strings in the action-setup step.

Sources

  1. github.com/advisories/ghsa-qmg3-hpqr-gqvc
  2. wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup
  3. cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free