Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

GitHub Action tj-actions/changed-files supply chain attack: what you need to know

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Dimitri Stiliadis
Word Count
840
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

A recent security breach involving the tj-actions/changed-files GitHub Action, used in over 23,000 repositories, has raised significant concerns within the developer community. Attackers introduced a malicious commit that affected multiple version tags, leading to the execution of a Python script capable of leaking CI/CD secrets. This incident, identified as CVE-2025-30066, has impacted public GitHub repositories with GitHub Actions enabled, prompting GitHub to remove the compromised Action and necessitating users to seek alternative implementations. Although GitHub has since restored the repository without the malicious code, the breach has highlighted vulnerabilities in the software supply chain, potentially affecting thousands of open-source packages. Developers and organizations are advised to audit their GitHub logs, search dependencies for the compromised Action, and rotate any exposed secrets to mitigate further risks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.