A GitHub Actions supply-chain attack compromised widely used actions including tj-actions/changed-files and components in the reviewdog ecosystem after attackers abused insecure workflow patterns to steal maintainer personal access tokens and move trusted tags to malicious code. Investigators traced the intrusion to a malicious pull request against the SpotBugs ecosystem using the dangerous pull_request_target trigger, which exposed a maintainer token that was later used to implant another workflow, steal additional tokens, and overwrite action tags. The malicious action chain leaked CI/CD secrets and environment variables by dumping runner memory into workflow logs, affecting downstream repositories at scale and including a targeted attempt involving Coinbase, which said the incident did not damage its assets.
Separate research showed that GitHub Actions integrations with Azure via OpenID Connect can also be undermined when federated identity credentials trust unsafe subject identifiers such as unprotected branches, tags, environments, or especially pull_request, allowing contributors to obtain Azure access tokens under weak configurations. The analysis found that even reusable workflows constrained with job_workflow_ref can still expose cloud access if the workflow permits caller-controlled code execution through mechanisms such as script injection or Terraform plan behavior. Together, the findings show that GitHub Actions trust boundaries can fail both in software supply chains and cloud federation unless organizations pin actions to commit SHAs, protect refs, minimize token permissions, validate reusable workflows, and enforce least-privilege access to secrets and cloud roles.

Trace attribution and downstream blast radius.
12 events from the most recent confirmed update back to the earliest known activity.
On March 21, 2025, Palo Alto Networks Unit 42 published an assessment describing the multi-stage GitHub Actions supply-chain attack affecting tj-actions/changed-files and reviewdog-related actions.
By March 20, 2025, maintainers of tj-actions and reviewdog had applied mitigations in response to the supply-chain attack.
On March 18, 2025, the reviewdog maintainer published a security advisory about the incident, formally disclosing compromise activity affecting reviewdog actions.
StepSecurity researchers detected suspicious activity and reported the compromise of tj-actions/changed-files on March 14, 2025. The malicious payload dumped CI/CD runner memory and exposed environment variables and secrets in workflow logs.
A maintainer deleted coinbase/agentkit's changelog.yml workflow on March 14, 2025 after it was identified as referencing v39 of tj-actions/changed-files.
coinbase/agentkit executed a malicious tj-actions/changed-files SHA on March 14, 2025 in a workflow running with write-all permissions. Investigators also reported the attacker obtained a write-capable GitHub token for coinbase/agentkit at 15:10 UTC that day.
The same iLrmKCu86tjwp8 account forked reviewdog/action-typos on 2025-03-11 17:21:52 UTC and pushed 15 commits with payload variations, indicating broader compromise activity in the reviewdog ecosystem.
A GitHub account named iLrmKCu86tjwp8 forked reviewdog/action-setup on 2025-03-11 17:06:12 UTC and pushed 13 commits with payload variations, establishing malicious infrastructure used in the supply-chain attack.
After inserting the malicious code, the attacker overrode existing git tags in tj-actions/changed-files so they pointed to the malicious commit, expanding impact to workflows that referenced tags rather than pinned SHAs.
Between March 10 and March 14, 2025, an attacker pushed malicious commit 0e58ed8 to tj-actions/changed-files using a GitHub token with write permissions. The commit was disguised as if created by renovate[bot] and merged through an auto-merge workflow.
Investigators observed attacker-linked activity connected to Coinbase through forks of coinbase/onchainkit, coinbase/agentkit, and coinbase/x402 created on March 12–13, 2025, suggesting reconnaissance or preparation for targeted abuse.
An April 2, 2025 update attributed reviewdog's compromise to a leaked personal access token belonging to a reviewdog maintainer, identified in the report as RD_MNTNR.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
binarysecurity.no
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.