Skip to main content
Back to overview
Medium

Supply Chain Attack on GitHub Action 'tj-actions/changed-files' Leaks CI/CD Secrets

A supply chain attack compromised the popular 'tj-actions/changed-files' GitHub Action, impacting over 23,000 repositories.

Key points

  • Malicious code injected into 'tj-actions/changed-files' GitHub Action.
  • Attack occurred between March 10 and March 14, 2025.
  • Affected over 23,000 repositories, with 218 confirmed to have leaked secrets.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Explore attack patterns

Threat source not confirmed

03

Potential impact

Potential business exposure

Impact remains under assessment

Published
Mar 10, 2025
Updated
Jun 26, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

Structured signal analysis is not available for this incident yet. It will appear here when enough industry or incident-pattern metadata is available.

Quick context

Questions about this signal

What happened in this signal?

A supply chain attack compromised the popular 'tj-actions/changed-files' GitHub Action, impacting over 23,000 repositories. Attackers injected malicious code that exfiltrated CI/CD secrets, GitHub tokens, API keys, and other credentials by printing them directly into workflow logs. The attack began on March 10, 2025, and was detected on March 14, 2025, with public reporting starting around March 10-14, 2025.

When was this signal reported?

Shadow Tier lists Mar 10, 2025 as the signal date.

Which organization is connected to this signal?

Github is the organization connected to this public signal.

Explore Github