tj-actions | changed-files GitHub Action
tj-actions/changed-files GitHub Action Embedded Malicious Code
Vulnerability: tj-actions/changed-files
GitHub Action contains an embedded malicious code vulnerability
that allows a remote attacker to discover secrets by reading
Github Actions Workflow Logs. These secrets may include, but are
not limited to, valid AWS access keys, GitHub personal access
tokens (PATs), npm tokens, and private RSA keys.
Known To Be Used in Ransomware Campaigns? Unknown
Action: Apply mitigations as set forth in the CISA
instructions linked below. Apply mitigations per vendor
instructions, follow applicable BOD 22-01 guidance for cloud
services, or discontinue use of the product if mitigations
are unavailable.
-
Date Added: 2025-03-18
-
Due Date: 2025-04-08
Additional Notes