The popular GitHub Action tj-actions/changed-files was compromised in a software supply-chain attack that redirected multiple release tags to a malicious commit, 0e58ed8671d6b60d0890c21b07f8835ace038e67, causing affected workflows to dump CI secrets into GitHub Actions logs. Early reporting indicated that all versions might be affected because tags in the repository had been moved to the attacker-controlled commit, prompting maintainers and defenders to urge organizations to immediately stop using the action, review workflow runs, and rotate any credentials that may have been exposed. GitHub later tracked the incident as CVE-2025-30066, and the project retagged releases and published v46.0.1 with guidance to pin only to a known-safe immutable commit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
During an internal response described by Semgrep, the company rescanned publicly invocable GitHub Actions, found at least one exploitable action in its own environment, and patched it. The effort was part of a broader review prompted by compromises affecting peer security vendors.
A malicious commit, 0e58ed8671d6b60d0890c21b07f8835ace038e67, was present in the tj-actions/changed-files repository and later identified as the commit to which compromised tags pointed.
Following the compromise, tj-actions retagged releases and published version 46.0.1, with guidance to pin to a known-safe immutable commit. This was the maintainer's remediation step for affected users.
Semgrep later reported that GitHub published an advisory for CVE-2025-30066 covering the tj-actions/changed-files compromise. This formalized public vulnerability tracking for the incident.
A later update in Semgrep's coverage stated that the malicious gist used in the tj-actions/changed-files attack chain had been removed. This disrupted part of the attacker infrastructure involved in the compromise.
On March 14, 2025, Semgrep published an alert stating that all versions were believed compromised because repository tags pointed to the malicious commit 0e58ed8. The post warned that the action attempted to dump CI secrets to workflow logs and urged organizations to stop using it, audit runs, and rotate secrets.
On March 14, 2025, a GitHub issue was opened reporting that multiple tags in tj-actions/changed-files were compromised. This publicly documented the tag compromise in the action's repository.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
semgrep.dev
Open sourcegithub.com
Open sourcesemgrep.dev
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.