The tj-actions/changed-files GitHub Action Supply Chain Attack

Updated 5 Oct 2026 · Incident date 14 Mar 2025 · CI action

Packagetj-actions/changed-files - all tags through v45.0.7 repointed to commit 0e58ed8; fixed in v46.0.1
Filedist/index.js

On 14 March 2025, an attacker repointed the version tags of the GitHub Action tj-actions/changed-files to a malicious commit. Every version through v45.0.7 was affected. The fix is v46.0.1. The CVE is CVE-2025-30066.

The commit read secrets from the CI runner and printed them in the workflow logs. The GitHub advisory counts over 23,000 repositories that used the action.

What happened

An attacker stole a token for the action's bot account, added a malicious commit and moved the release tags to it. StepSecurity reports that the attacker compromised a personal access token (PAT) for the @tj-actions-bot account and updated all release tags to the malicious commit, 0e58ed8671d6b60d0890c21b07f8835ace038e67.

The code ran a Python script that downloaded a memory-dump script from a GitHub gist. The script read the memory of the Actions Runner process through /proc/{pid}/mem and printed the secrets it found, Base64-encoded, into the workflow log. In public repositories, anyone can read the log.

Unit 42 traced the chain back further. According to Unit 42, the attacker first leaked a SpotBugs maintainer token through a pull_request_target workflow. It then reached the reviewdog action setup, and from there the token for tj-actions/changed-files. Unit 42 states that Coinbase's agentkit repository was the first target of the code.

StepSecurity dates the start of the incident to about 16:00 UTC on 14 March 2025. GitHub removed the action on 15 March at about 14:00 UTC. The maintainers restored the repository about eight hours later and cleaned the malicious code.

Vigilance compares the version you trust with the new one. A tag that now points to different code is a change in the files an action runs. Vigilance reports the file that gained a new capability. See the scan block below.

Affected versions

Indicators of compromise

How to check

Find every workflow that uses the action and see how it is pinned.

grep -rn "tj-actions/changed-files" .github/workflows

A line with a tag such as @v44 was exposed. A line that pins a full commit SHA from before the attack was not. Then open the logs of runs from 14 and 15 March 2025 and look for a large Base64 block in the changed-files step.

What to do now

  1. Remove the action or update to v46.0.1. StepSecurity also offers a drop-in fork, step-security/changed-files@v45.
  2. Review the logs of workflows that ran on 14 and 15 March 2025. Delete or restrict logs that show secrets.
  3. Rotate every secret that those workflows can read. This includes cloud keys, tokens and SSH keys.
  4. Pin actions to a full commit SHA, not to a tag.
  5. Restrict which actions your organization can run. Use OpenID Connect for cloud sign-in instead of long-lived keys.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old tj-actions/changed-files-prev --new tj-actions/changed-files-current
files scanned: 66

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    dist/index.js
           It now downloads from the internet, reads saved passwords and access keys and runs a hidden, encoded command. It did not before.

Frequently asked questions

Which versions of tj-actions/changed-files were compromised?

The GitHub advisory lists all versions through v45.0.7. The attacker moved existing tags to a malicious commit. Version v46.0.1 is the patched release.

How do I know if my workflows leaked secrets in the tj-actions attack?

Check the logs of runs on 14 and 15 March 2025 for a large Base64 block printed by the changed-files step. Treat all secrets that the workflow can read as exposed.

Sources

  1. github.com/advisories/ghsa-mrrh-fwg8-r2c3
  2. stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
  3. unit42.paloaltonetworks.com/github-actions-supply-chain-attack/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free