Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› tj-actions/changed-files Compromise 2025: How a Stolen Bot Token…
Breach analysis Incident: 14 Mar 2025

tj-actions/changed-files Compromise 2025: How a Stolen Bot Token Leaked CI/CD Secrets from Thousands of Repositories

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
On this page

On 14 March 2025, StepSecurity detected that tj-actions/changed-files, a GitHub Action used in more than 23,000 repositories, had been compromised. An attacker had used a stolen Personal Access Token (PAT) belonging to the project's bot account to add a malicious commit and repoint almost every version tag at it. Any workflow that ran the Action then executed a script that dumped the GitHub Actions runner's memory and printed the CI/CD secrets it held, including cloud access keys, GitHub PATs, npm tokens and private RSA keys, into the build log. For public repositories, those logs were readable by anyone. The flaw was tracked as CVE-2025-30066 and added to CISA's Known Exploited Vulnerabilities catalogue. Later research by Unit 42 found this was the third stage of a longer chain that began with a leaked SpotBugs token and passed through reviewdog, with Coinbase as the apparent original target.

Key takeaways

  • An attacker used a stolen PAT for the tj-actions bot account to push a malicious commit and repoint the Action's release tags to it.
  • The payload dumped CI runner memory and printed secrets to workflow logs, which were public for public repositories.
  • Exposed secrets included access keys, GitHub PATs, npm tokens and private RSA keys, according to CISA.
  • Unit 42 traced the stolen token to the earlier compromise of reviewdog/action-setup, which itself began with a SpotBugs maintainer's leaked PAT.
  • The identity lesson: one long-lived token with write access to a widely used Action is a key to every pipeline that trusts it.

At a glance

Organisationstj-actions (maintainers of tj-actions/changed-files); more than 23,000 repositories using the Action; Coinbase (apparent original target)
WhenCISA audit window 12 to 15 March 2025; detected by StepSecurity on 14 March 2025
AttackerUnattributed; Unit 42 found the campaign initially targeted Coinbase
Entry pointA stolen GitHub PAT for the tj-actions bot account, obtained through the compromised reviewdog/action-setup Action
Identities abusedThe tj-actions bot PAT; CI/CD secrets in the workflows of repositories using the Action, including access keys, PATs, npm tokens and private RSA keys
ImpactCI/CD secrets printed to workflow logs; secrets exposed for 218 repositories, according to BleepingComputer; CVE-2025-30066 added to CISA's KEV catalogue
CategoryNHI. Incident class: confirmed NHI breach (stolen bot token used to poison a CI/CD dependency and leak pipeline secrets)

What happened

StepSecurity's Harden-Runner flagged an unexpected network endpoint in workflows using tj-actions/changed-files, and its investigation found that "most versions" of the Action were compromised. "The adversary compromised a Personal Access Token (PAT) linked to the @tj-actions-bot bot account," StepSecurity wrote, and then pointed all release tags at a single malicious commit. That commit ran a Python script that read the memory of the runner's Runner.Worker process and extracted every value marked as a secret, then printed them to the log, double-encoded in base64. StepSecurity said "There is no evidence that the leaked secrets were exfiltrated to any remote network destination."

Unit 42 described how the attacker added the malicious commit using "a GitHub token with write permissions that they obtained previously," disguised it as coming from renovate[bot] and slipped it into a legitimate automated pull request that was merged automatically. It then pushed new tags so all of them pointed at the malicious commit. CISA's alert advised auditing all workflows that ran tj-actions/changed-files between "2025-03-12 00:00 UTC to 2025-03-15 12:00 UTC," and treating any exposed secrets as compromised. GitHub removed the Action on 15 March and restored a cleaned repository later that day, StepSecurity reported.

The source of the token was traced back further. Unit 42 confirmed that tj-actions/changed-files' own CI ran tj-actions/eslint-changed-files, which depended on reviewdog/action-setup. When that Action was compromised, the runner's secrets leaked, "including a Personal Access Token (PAT) belonging to the tj-bot-actions GitHub user account." Unit 42 also found the attacker first pointed a tag at a commit aimed at Coinbase's agentkit repository, whose workflow then ran with write permissions. Coinbase said the attack did not cause damage to agentkit or any other Coinbase asset. See our pages on the reviewdog stage and the SpotBugs root cause.

Timeline

DateEvent
11 March 2025reviewdog/action-setup is compromised; the tj-actions bot PAT later leaks through it.
12 March 2025Start of CISA's exposure window for tj-actions/changed-files.
14 March 2025StepSecurity detects the compromise and finds public repositories leaking secrets in logs.
15 March 2025GitHub removes the Action, then restores a cleaned repository.
18 March 2025CISA publishes an alert on CVE-2025-30066.
20 March 2025Unit 42 publishes its analysis linking the attack to reviewdog and Coinbase.

How it happened: the identity attack path

  1. Token stolen upstream. The compromised reviewdog Action leaked the tj-actions bot PAT from tj-actions' own CI run.
  2. Malicious commit. The attacker used the PAT to add a commit disguised as renovate[bot] via an auto-merged pull request.
  3. Tags repointed. Version tags were moved to the malicious commit, so pinned-by-tag users received it.
  4. Secrets dumped. Every workflow that ran the Action printed its secrets to the build log.
  5. Exposure. In public repositories, anyone could read the logs and decode the secrets.

Impact

  • Exposed: CI/CD secrets in workflows that ran the Action during the window, including access keys, GitHub PATs, npm tokens and private RSA keys.
  • Scale: the Action was used by more than 23,000 repositories; BleepingComputer later reported that the malicious commit exposed secrets for 218 repositories.
  • Targeted attempt: Coinbase's agentkit workflow consumed the malicious tag; Coinbase said no damage was caused.

What this means for NHI governance

This attack ran on non-human identities at every step. A bot account's PAT gave write access to a popular Action. The Action ran inside thousands of pipelines, each holding its own cloud keys, registry tokens and signing keys. A single long-lived token was enough to reach all of them, and the tag-based versioning most users relied on meant nobody had to approve the change.

Reducing that exposure means treating CI/CD tokens and third-party Actions as identities with privileges: short-lived, narrowly scoped tokens for bots; pinning Actions to commit SHAs; allow-listing which Actions can run; and keeping high-value secrets out of workflows that run third-party code. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.

Recommendations

  • Pin Actions to full commit SHAs. Tags can be repointed; SHAs cannot. See the CI/CD Pipeline Identity Security Guide.
  • Rotate secrets exposed in logs. Check workflow runs during the exposure window and treat any printed secret as compromised. See the Leaked Credential Response Playbook.
  • Replace long-lived bot PATs. Use short-lived, scoped tokens such as GitHub App tokens or OIDC. See our NHI Authentication Guide.
  • Allow-list third-party Actions. Only approved Actions should run in your organisation.
  • Monitor runner network traffic. Unexpected endpoints were how this attack was detected. See the ITDR Guide.

Frequently asked questions

What happened to tj-actions/changed-files?

In March 2025 an attacker used a stolen bot token to repoint the Action's version tags to a malicious commit that printed CI/CD secrets into workflow logs. It is tracked as CVE-2025-30066.

How was the tj-actions token stolen?

Unit 42 found it leaked when tj-actions' own CI ran the compromised reviewdog/action-setup Action, which dumped the runner's secrets, including the bot's PAT.

What should affected users do?

Find workflows that ran the Action between 12 and 15 March 2025, rotate any secrets that appeared in logs, pin Actions to commit SHAs and review logs for other suspicious activity.

SpotBugs Token Leak 2025 · reviewdog Action Compromise 2025 · Megalodon GitHub Actions Attack 2026 · CI/CD Pipeline Identity Security Guide · Secrets Management Guide

How NHI Mgmt Group can help

CI/CD pipelines hold some of the most powerful credentials in an organisation. We help teams inventory pipeline tokens, replace long-lived ones and control which third-party code can reach them. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org