The popular GitHub Action tj-actions/changed-files has been compromised

ISGroup Cybersecurity

The popular GitHub Action tj-actions/changed-files has been compromised by a malicious payload that appears to attempt to export repository secrets, with the potential to impact thousands of CI pipelines on GitHub. As of March 14, 2025, all versions of this action are believed to be compromised. This is not the first security issue associated with this action—a previous vulnerability (CVE-2023-51664) had already been reported.

The action is widely used in CI/CD workflows to detect which files have been modified between commits, making it a high-value target for attackers interested in extracting sensitive information from repositories.

Date2025-03-16 01:30:55
Information
  • Active Exploitation

Technical Summary

The compromise involves a malicious payload injected into the action’s code at commit 0e58ed8. When the compromised action is executed in a workflow, it attempts to exfiltrate secrets by writing them to stdout, which is particularly dangerous in repositories with public CI runner logs.

The attack exploits the broad trust placed in this action and the extensive permissions typically granted to GitHub Actions workflows. Since in most implementations the action is referenced by tag rather than by commit SHA, users are automatically exposed to the compromised version as soon as the tag is updated, without having to modify workflow files.

The payload specifically targets CI environment variables and secrets, which often contain sensitive authentication tokens, API keys, and other credentials that could grant an attacker access to various systems and services.

Recommendations

Immediate actions:

Identify compromised repositories by:

  • Searching your code for references to tj-actions
  • Using the GitHub search query: https://github.com/search?q=org%3A<YOURORG>+uses%3A+tj-actions%2F&type=code

Immediately remove the compromised action from:

  • All branches (not just the main one)
  • All workflow files (.github/workflows/*.yml)

Implement preventive measures:

  • Configure GitHub organization settings to allow only secure actions (allow-list)
  • Remove tj-actions/changed-files from the list of allowed actions
  • Pin remaining GitHub Actions to specific commit SHAs instead of version tags

Use alternatives:

  • Switch to a more secure GitHub Action alternative
  • Consider implementing inline logic for file change detection
  • For Semgrep AppSec Platform users, immediately enable blocking mode for the detection rule

Remember that removing the action only from the main branch is not enough—it must be completely deleted from all workflows to prevent its execution in any context.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert