GitHub Action tj-actions/changed-files supply chain attack: what you need to know
Blog post from Endor Labs
A recent security breach involving the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, has raised significant concerns within the developer community. Attackers introduced a malicious commit that affected multiple version tags, leading to the execution of a Python script capable of leaking CI/CD secrets. This incident, identified as CVE-2025-30066, has impacted public GitHub repositories with GitHub Actions enabled, prompting GitHub to remove the compromised Action and necessitating users to seek alternative implementations. Although GitHub has since restored the repository without the malicious code, the breach has highlighted vulnerabilities in the software supply chain, potentially affecting thousands of open-source packages. Developers and organizations are advised to audit their GitHub logs, search dependencies for the compromised Action, and rotate any exposed secrets to mitigate further risks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.