On 11 March 2025, for about two hours, the v1 tag of reviewdog/action-setup, a GitHub Action used to install the reviewdog code review tool and a building block of several other reviewdog Actions, pointed to a malicious commit. Any workflow that ran it during that window executed a payload that dumped the CI runner's memory and printed the workflow's secrets into its logs. Wiz Research disclosed the compromise on 17 March 2025, while investigating the larger tj-actions/changed-files attack, and it was tracked as CVE-2025-30154. The two were connected: tj-actions' own CI used reviewdog/action-setup, and the secrets it leaked included the tj-actions bot token that the attacker then used for the next stage. Palo Alto Networks Unit 42 later found that the reviewdog tag had been moved with a maintainer's Personal Access Token (PAT), stolen earlier from the SpotBugs project.
Key takeaways
- reviewdog/action-setup@v1 pointed to a malicious commit on 11 March 2025 between 18:42 and 20:31 UTC, according to Wiz and CISA.
- The payload dumped runner memory and printed secrets to workflow logs, visible to anyone for public repositories.
- Several other reviewdog Actions that use action-setup, such as action-shellcheck and action-typos, were also affected.
- Unit 42 found the attacker used a reviewdog maintainer's PAT, leaked earlier from SpotBugs, to move the tag.
- The identity lesson: one maintainer token with write access across several projects linked two open source organisations into one attack path.
At a glance
| Organisations | reviewdog (maintainers of reviewdog/action-setup and related Actions); repositories using the affected Actions, including tj-actions/changed-files |
|---|---|
| When | Malicious tag in place 11 March 2025, 18:42 to 20:31 UTC; disclosed by Wiz on 17 March 2025 |
| Attacker | Unattributed; the same actor as the tj-actions compromise, according to Unit 42 |
| Entry point | A reviewdog maintainer's GitHub PAT, leaked earlier from the SpotBugs repository |
| Identities abused | The maintainer's PAT; CI/CD secrets in workflows that ran the Action, including the tj-actions bot PAT |
| Impact | Secrets printed to workflow logs; the leaked tj-actions token enabled the tj-actions/changed-files compromise; CVE-2025-30154 added to CISA's KEV catalogue |
| Category | NHI. Incident class: confirmed NHI breach (stolen maintainer token used to poison a CI/CD dependency) |
What happened
Following a lead from researcher Adnan Khan, Wiz found that "the v1 tag of the reviewdog/action-setup Github Action was compromised in the lead up to the tj-actions incident." Like the later attack, the payload dumped runner memory containing workflow secrets, but it was delivered differently: "the payload was base64 encoded and directly inserted into the install.sh file used by the workflow." Wiz believed the tag "was pointed to a malicious commit on March 11th between 18:42 and 20:31 UTC" before being reverted, possibly by the attacker to cover their tracks. As with tj-actions, Wiz observed no external exfiltration: secrets were "only observable within the affected repositories themselves."
Because other reviewdog Actions use action-setup as a component, CISA listed reviewdog/action-shellcheck, action-composite-template, action-staticcheck, action-ast-grep and action-typos as possibly affected, and advised organisations to audit workflows that ran during the window and rotate exposed secrets. Wiz noted that users who pinned action-setup to a commit hash, or to a different tag, were not affected.
The link to tj-actions was direct. tj-actions/changed-files ran tj-actions/eslint-changed-files in its own CI, which depended on reviewdog/action-setup, "and the tj-actions/changed-files repository runs this tj-actions/eslint-changed-files Action with a Personal Access Token," Wiz explained. Unit 42 confirmed the stolen tj-actions bot PAT came from this run. As for how the reviewdog tag was moved, Wiz reported that the maintainer, with GitHub's help, found that a user account "was not maliciously added via the previously discussed Invite workflow, but rather itself compromised." Unit 42's April update traced this to a maintainer's PAT leaked from spotbugs/spotbugs, which "had permissions to both of these repositories." See the SpotBugs root cause and the tj-actions stage.
Timeline
| Date | Event |
|---|---|
| 11 March 2025 | reviewdog/action-setup@v1 points to a malicious commit between 18:42 and 20:31 UTC. |
| 14 March 2025 | The tj-actions/changed-files compromise, enabled by a token leaked through reviewdog, is detected. |
| 17 March 2025 | Wiz discloses the reviewdog compromise. |
| 18 March 2025 | CISA publishes an alert covering both Actions. |
| 19 March 2025 | The issue is assigned CVE-2025-30154. |
| 2 April 2025 | Unit 42 publishes the SpotBugs origin of the maintainer token. |
How it happened: the identity attack path
- Maintainer token stolen. A PAT belonging to a maintainer of both SpotBugs and reviewdog leaked from a SpotBugs workflow.
- Tag moved. The attacker used it to point reviewdog/action-setup@v1 at a malicious commit from a fork.
- Secrets dumped. Workflows running the Action printed their secrets to build logs.
- Next token harvested. tj-actions' CI ran the Action and leaked the tj-actions bot PAT.
- Tag reverted. The tag returned to an old commit after about two hours.
Impact
- Exposed: secrets in workflows that ran reviewdog/action-setup@v1 or dependent reviewdog Actions during the window.
- Downstream: the leaked tj-actions bot PAT enabled the tj-actions/changed-files compromise.
- Exfiltration: none observed to an external server, according to Wiz.
What this means for NHI governance
The reviewdog stage shows how tokens link projects. One maintainer's PAT had write access to repositories in two organisations, and a CI run in one project leaked the token that opened the next. Each hop used a credential, not a vulnerability. The Action's short compromise window did not limit the damage, because the secret it harvested was long-lived.
Maintainers should use fine-grained tokens limited to one repository, and projects that consume Actions should pin to commit SHAs and keep powerful tokens out of workflows that run third-party code. See our CI/CD Pipeline Identity Security Guide and NHI Authentication Guide.
Recommendations
- Pin Actions to commit SHAs. Tag-based references followed the malicious commit automatically. See the CI/CD Pipeline Identity Security Guide.
- Scope maintainer tokens to one repository. Fine-grained PATs or GitHub Apps limit how far one leak reaches. See our NHI Authentication Guide.
- Keep powerful tokens out of third-party steps. Do not pass PATs to workflows that run external Actions.
- Rotate secrets from affected runs. Check logs for the double-encoded payload and rotate what appears. See the Leaked Credential Response Playbook.
- Review contributor access regularly. Large contributor bases increase the chance of a compromised account. See the Access Reviews Guide.
Frequently asked questions
What was the reviewdog GitHub Action compromise?
On 11 March 2025, the v1 tag of reviewdog/action-setup pointed to malicious code for about two hours, causing workflows to print their secrets to logs. It is tracked as CVE-2025-30154.
How is reviewdog linked to tj-actions?
tj-actions' own CI used reviewdog/action-setup. When it ran the compromised version, the tj-actions bot token leaked, and the attacker used it to compromise tj-actions/changed-files.
How did the attacker compromise reviewdog?
Unit 42 found the attacker used a maintainer's PAT that had leaked earlier from the SpotBugs project and had access to both repositories.
Related NHI Mgmt Group resources
SpotBugs Token Leak 2025 · tj-actions/changed-files Compromise 2025 · CI/CD Pipeline Identity Security Guide · NHI Authentication Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Open source maintainers and the teams that depend on them share the same token risk. We help teams scope pipeline tokens, pin dependencies and respond quickly when an upstream Action is compromised. See our NHI and AI agent security training.
References
- Wiz: GitHub Action supply chain attack: reviewdog/action-setup (17 March 2025)
- CISA: Supply Chain Compromise of Third-Party tj-actions/changed-files (CVE-2025-30066) and reviewdog/action-setup@v1 (CVE-2025-30154) (18 March 2025)
- Palo Alto Networks Unit 42: GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident (20 March 2025)