Supply Chain Attack on GitHub Action 'tj-actions/changed-files' Leaks CI/CD Secrets
A supply chain attack compromised the popular 'tj-actions/changed-files' GitHub Action, impacting over 23,000 repositories.
Key points
- Malicious code injected into 'tj-actions/changed-files' GitHub Action.
- Attack occurred between March 10 and March 14, 2025.
- Affected over 23,000 repositories, with 218 confirmed to have leaked secrets.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Mar 10, 2025
- Updated
- Jun 26, 2026
- Confidence
- Medium
- Evidence
- 1 source
Structured assessment
Signal analysis
Quick context
Questions about this signal
What happened in this signal?
A supply chain attack compromised the popular 'tj-actions/changed-files' GitHub Action, impacting over 23,000 repositories. Attackers injected malicious code that exfiltrated CI/CD secrets, GitHub tokens, API keys, and other credentials by printing them directly into workflow logs. The attack began on March 10, 2025, and was detected on March 14, 2025, with public reporting starting around March 10-14, 2025.
When was this signal reported?
Shadow Tier lists Mar 10, 2025 as the signal date.
Which organization is connected to this signal?
Github is the organization connected to this public signal.
Explore Github