On 14 March 2025, StepSecurity detected that tj-actions/changed-files, a GitHub Action used in more than 23,000 repositories, had been compromised. An attacker had used a stolen Personal Access Token (PAT) belonging to the project's bot account to add a malicious commit and repoint almost every version tag at it. Any workflow that ran the Action then executed a script that dumped the GitHub Actions runner's memory and printed the CI/CD secrets it held, including cloud access keys, GitHub PATs, npm tokens and private RSA keys, into the build log. For public repositories, those logs were readable by anyone. The flaw was tracked as CVE-2025-30066 and added to CISA's Known Exploited Vulnerabilities catalogue. Later research by Unit 42 found this was the third stage of a longer chain that began with a leaked SpotBugs token and passed through reviewdog, with Coinbase as the apparent original target.
Key takeaways
- An attacker used a stolen PAT for the tj-actions bot account to push a malicious commit and repoint the Action's release tags to it.
- The payload dumped CI runner memory and printed secrets to workflow logs, which were public for public repositories.
- Exposed secrets included access keys, GitHub PATs, npm tokens and private RSA keys, according to CISA.
- Unit 42 traced the stolen token to the earlier compromise of reviewdog/action-setup, which itself began with a SpotBugs maintainer's leaked PAT.
- The identity lesson: one long-lived token with write access to a widely used Action is a key to every pipeline that trusts it.
At a glance
| Organisations | tj-actions (maintainers of tj-actions/changed-files); more than 23,000 repositories using the Action; Coinbase (apparent original target) |
|---|---|
| When | CISA audit window 12 to 15 March 2025; detected by StepSecurity on 14 March 2025 |
| Attacker | Unattributed; Unit 42 found the campaign initially targeted Coinbase |
| Entry point | A stolen GitHub PAT for the tj-actions bot account, obtained through the compromised reviewdog/action-setup Action |
| Identities abused | The tj-actions bot PAT; CI/CD secrets in the workflows of repositories using the Action, including access keys, PATs, npm tokens and private RSA keys |
| Impact | CI/CD secrets printed to workflow logs; secrets exposed for 218 repositories, according to BleepingComputer; CVE-2025-30066 added to CISA's KEV catalogue |
| Category | NHI. Incident class: confirmed NHI breach (stolen bot token used to poison a CI/CD dependency and leak pipeline secrets) |
What happened
StepSecurity's Harden-Runner flagged an unexpected network endpoint in workflows using tj-actions/changed-files, and its investigation found that "most versions" of the Action were compromised. "The adversary compromised a Personal Access Token (PAT) linked to the @tj-actions-bot bot account," StepSecurity wrote, and then pointed all release tags at a single malicious commit. That commit ran a Python script that read the memory of the runner's Runner.Worker process and extracted every value marked as a secret, then printed them to the log, double-encoded in base64. StepSecurity said "There is no evidence that the leaked secrets were exfiltrated to any remote network destination."
Unit 42 described how the attacker added the malicious commit using "a GitHub token with write permissions that they obtained previously," disguised it as coming from renovate[bot] and slipped it into a legitimate automated pull request that was merged automatically. It then pushed new tags so all of them pointed at the malicious commit. CISA's alert advised auditing all workflows that ran tj-actions/changed-files between "2025-03-12 00:00 UTC to 2025-03-15 12:00 UTC," and treating any exposed secrets as compromised. GitHub removed the Action on 15 March and restored a cleaned repository later that day, StepSecurity reported.
The source of the token was traced back further. Unit 42 confirmed that tj-actions/changed-files' own CI ran tj-actions/eslint-changed-files, which depended on reviewdog/action-setup. When that Action was compromised, the runner's secrets leaked, "including a Personal Access Token (PAT) belonging to the tj-bot-actions GitHub user account." Unit 42 also found the attacker first pointed a tag at a commit aimed at Coinbase's agentkit repository, whose workflow then ran with write permissions. Coinbase said the attack did not cause damage to agentkit or any other Coinbase asset. See our pages on the reviewdog stage and the SpotBugs root cause.
Timeline
| Date | Event |
|---|---|
| 11 March 2025 | reviewdog/action-setup is compromised; the tj-actions bot PAT later leaks through it. |
| 12 March 2025 | Start of CISA's exposure window for tj-actions/changed-files. |
| 14 March 2025 | StepSecurity detects the compromise and finds public repositories leaking secrets in logs. |
| 15 March 2025 | GitHub removes the Action, then restores a cleaned repository. |
| 18 March 2025 | CISA publishes an alert on CVE-2025-30066. |
| 20 March 2025 | Unit 42 publishes its analysis linking the attack to reviewdog and Coinbase. |
How it happened: the identity attack path
- Token stolen upstream. The compromised reviewdog Action leaked the tj-actions bot PAT from tj-actions' own CI run.
- Malicious commit. The attacker used the PAT to add a commit disguised as renovate[bot] via an auto-merged pull request.
- Tags repointed. Version tags were moved to the malicious commit, so pinned-by-tag users received it.
- Secrets dumped. Every workflow that ran the Action printed its secrets to the build log.
- Exposure. In public repositories, anyone could read the logs and decode the secrets.
Impact
- Exposed: CI/CD secrets in workflows that ran the Action during the window, including access keys, GitHub PATs, npm tokens and private RSA keys.
- Scale: the Action was used by more than 23,000 repositories; BleepingComputer later reported that the malicious commit exposed secrets for 218 repositories.
- Targeted attempt: Coinbase's agentkit workflow consumed the malicious tag; Coinbase said no damage was caused.
What this means for NHI governance
This attack ran on non-human identities at every step. A bot account's PAT gave write access to a popular Action. The Action ran inside thousands of pipelines, each holding its own cloud keys, registry tokens and signing keys. A single long-lived token was enough to reach all of them, and the tag-based versioning most users relied on meant nobody had to approve the change.
Reducing that exposure means treating CI/CD tokens and third-party Actions as identities with privileges: short-lived, narrowly scoped tokens for bots; pinning Actions to commit SHAs; allow-listing which Actions can run; and keeping high-value secrets out of workflows that run third-party code. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.
Recommendations
- Pin Actions to full commit SHAs. Tags can be repointed; SHAs cannot. See the CI/CD Pipeline Identity Security Guide.
- Rotate secrets exposed in logs. Check workflow runs during the exposure window and treat any printed secret as compromised. See the Leaked Credential Response Playbook.
- Replace long-lived bot PATs. Use short-lived, scoped tokens such as GitHub App tokens or OIDC. See our NHI Authentication Guide.
- Allow-list third-party Actions. Only approved Actions should run in your organisation.
- Monitor runner network traffic. Unexpected endpoints were how this attack was detected. See the ITDR Guide.
Frequently asked questions
What happened to tj-actions/changed-files?
In March 2025 an attacker used a stolen bot token to repoint the Action's version tags to a malicious commit that printed CI/CD secrets into workflow logs. It is tracked as CVE-2025-30066.
How was the tj-actions token stolen?
Unit 42 found it leaked when tj-actions' own CI ran the compromised reviewdog/action-setup Action, which dumped the runner's secrets, including the bot's PAT.
What should affected users do?
Find workflows that ran the Action between 12 and 15 March 2025, rotate any secrets that appeared in logs, pin Actions to commit SHAs and review logs for other suspicious activity.
Related NHI Mgmt Group resources
SpotBugs Token Leak 2025 · reviewdog Action Compromise 2025 · Megalodon GitHub Actions Attack 2026 · CI/CD Pipeline Identity Security Guide · Secrets Management Guide
How NHI Mgmt Group can help
CI/CD pipelines hold some of the most powerful credentials in an organisation. We help teams inventory pipeline tokens, replace long-lived ones and control which third-party code can reach them. See our NHI and AI agent security training.
References
- StepSecurity: Harden-Runner detection: tj-actions/changed-files action is compromised (14 March 2025)
- CISA: Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154) (18 March 2025)
- Palo Alto Networks Unit 42: GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident (20 March 2025)
- BleepingComputer: Recent GitHub supply chain attack traced to leaked SpotBugs token (3 April 2025)