He probably just re-pushed the bad commit while trying to figure out how to fix this.
I find it very plausible that the bot token was compromised, not his user account token, as the attack was simply to push over the tags (which is something the automation bot would have access to do, as tag management is one of its functions)