The tj-actions/changed-files GitHub Action Supply Chain Attack
Updated 5 Oct 2026 · Incident date 14 Mar 2025 · CI action
tj-actions/changed-files - all tags through v45.0.7 repointed to commit 0e58ed8; fixed in v46.0.1dist/index.jsOn 14 March 2025, an attacker repointed the version tags of the GitHub Action tj-actions/changed-files to a malicious commit. Every version through v45.0.7 was affected. The fix is v46.0.1. The CVE is CVE-2025-30066.
The commit read secrets from the CI runner and printed them in the workflow logs. The GitHub advisory counts over 23,000 repositories that used the action.
What happened
An attacker stole a token for the action's bot account, added a malicious commit and moved the release tags to it. StepSecurity reports that the attacker compromised a personal access token (PAT) for the @tj-actions-bot account and updated all release tags to the malicious commit, 0e58ed8671d6b60d0890c21b07f8835ace038e67.
The code ran a Python script that downloaded a memory-dump script from a GitHub gist. The script read the memory of the Actions Runner process through /proc/{pid}/mem and printed the secrets it found, Base64-encoded, into the workflow log. In public repositories, anyone can read the log.
Unit 42 traced the chain back further. According to Unit 42, the attacker first leaked a SpotBugs maintainer token through a pull_request_target workflow. It then reached the reviewdog action setup, and from there the token for tj-actions/changed-files. Unit 42 states that Coinbase's agentkit repository was the first target of the code.
StepSecurity dates the start of the incident to about 16:00 UTC on 14 March 2025. GitHub removed the action on 15 March at about 14:00 UTC. The maintainers restored the repository about eight hours later and cleaned the malicious code.
Vigilance compares the version you trust with the new one. A tag that now points to different code is a change in the files an action runs. Vigilance reports the file that gained a new capability. See the scan block below.
Affected versions
tj-actions/changed-filesthrough v45.0.7, according to the GitHub advisory. The advisory lists the vulnerable tags v1.0.0, v35.7.7-sec and v44.5.1 among them.- Patched in v46.0.1.
- The window ran on 14 and 15 March 2025. Workflows that ran in that window and used a tag, not a commit SHA, are the ones to review.
Indicators of compromise
- Malicious commit:
0e58ed8671d6b60d0890c21b07f8835ace038e67. - Outbound request to
gist.githubusercontent.com, for the filememdump.py. - A long Base64-encoded block in a workflow log, printed by the changed-files step.
- Workflow runs of the action on 14 or 15 March 2025.
How to check
Find every workflow that uses the action and see how it is pinned.
grep -rn "tj-actions/changed-files" .github/workflows
A line with a tag such as @v44 was exposed. A line that pins a full commit SHA from before the attack was not. Then open the logs of runs from 14 and 15 March 2025 and look for a large Base64 block in the changed-files step.
What to do now
- Remove the action or update to v46.0.1. StepSecurity also offers a drop-in fork,
step-security/changed-files@v45. - Review the logs of workflows that ran on 14 and 15 March 2025. Delete or restrict logs that show secrets.
- Rotate every secret that those workflows can read. This includes cloud keys, tokens and SSH keys.
- Pin actions to a full commit SHA, not to a tag.
- Restrict which actions your organization can run. Use OpenID Connect for cloud sign-in instead of long-lived keys.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 66 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED dist/index.js It now downloads from the internet, reads saved passwords and access keys and runs a hidden, encoded command. It did not before.
Frequently asked questions
Which versions of tj-actions/changed-files were compromised?
The GitHub advisory lists all versions through v45.0.7. The attacker moved existing tags to a malicious commit. Version v46.0.1 is the patched release.
How do I know if my workflows leaked secrets in the tj-actions attack?
Check the logs of runs on 14 and 15 March 2025 for a large Base64 block printed by the changed-files step. Treat all secrets that the workflow can read as exposed.
Sources
More supply chain attacks
- Trivy v0.69.4 and GitHub Actions compromise (TeamPCP) 19 Mar 2026
- reviewdog/action-setup compromise 11 Mar 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.