Executive brief
The tj-actions/changed-files GitHub Action was compromised by a threat actor who modified tags v1 through v45.0.7 to point to a malicious commit. The embedded malicious code (updateFeatures) allows remote attackers to exfiltrate secrets, such as AWS keys and GitHub PATs, by reading GitHub Actions workflow logs.
Affected products
- tj-actions changed-files v1 through v45.0.7
Timeline
- 2025-03-14: exploited: Malicious code injected into tags v1 through v45.0.7 by a threat actor.
- 2025-03-18: disclosed: CVE-2025-30066 published.
- 2025-03-18: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-03-19: patched: Version 46 and later are considered safe.