tj-actions/changed-files Compromise (Mar 2025): A GitHub Action Leaks CI Secrets
Retrospective: this article looks back at events from March 2025, written in 2026 with the benefit of hindsight.
On March 14, 2025, security researchers discovered that tj-actions/changed-files, a popular GitHub Action used in tens of thousands of repositories, had been compromised. The malicious version printed CI/CD secrets into build logs (CVE-2025-30066).
How it happened
Attackers modified the action's code and updated version tags (for example, v35 and others) to point to a malicious commit. Any workflow referencing the action by tag automatically ran the malicious code, which dumped secrets from the runner's memory into the workflow log. For public repositories, those logs were visible to anyone.
Investigations found the compromise likely originated from another action, reviewdog/action-setup, which was compromised first and used to steal a token with write access to tj-actions.
The malicious code was removed within days, but secrets exposed in public logs had to be treated as compromised.
Why it mattered
- Mutable tags meant workflows changed behavior without any change in the referencing repository.
- CI/CD secrets — cloud keys, package registry tokens, API keys — were exposed at scale.
- Supply-chain chaining: one compromised action led to another.
GitHub and community response
GitHub removed the compromised version, and CISA issued an alert. Guidance converged on pinning actions to full commit SHAs, restricting allowed actions and minimizing secrets in workflows.
Lessons in hindsight
- Pin third-party actions to commit SHAs, not tags.
- Allowlist approved actions at the organization level.
- Use OIDC federation instead of stored cloud secrets.
- Limit workflow token permissions (
permissions:set to read-only by default). - Rotate secrets whenever exposure is possible.
- How to Pin and Allowlist GitHub Actions in Cloud Deployment Pipelines How-To & Hardening
- Detecting GitHub Actions Supply Chain Attack: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Pipeline Supply-Chain Risk Explained CIO Briefings