Scan to download
BTC $76,884.60 -2.09%
ETH $2,288.88 -3.39%
BNB $623.67 -2.08%
XRP $1.39 -2.72%
SOL $84.35 -2.94%
TRX $0.3259 +0.69%
DOGE $0.0981 -1.27%
ADA $0.2454 -2.78%
BCH $448.12 -1.52%
LINK $9.23 -2.75%
HYPE $41.40 -1.40%
AAVE $96.39 -0.24%
SUI $0.9253 -2.27%
XLM $0.1658 -3.35%
ZEC $352.43 -0.85%
BTC $76,884.60 -2.09%
ETH $2,288.88 -3.39%
BNB $623.67 -2.08%
XRP $1.39 -2.72%
SOL $84.35 -2.94%
TRX $0.3259 +0.69%
DOGE $0.0981 -1.27%
ADA $0.2454 -2.78%
BCH $448.12 -1.52%
LINK $9.23 -2.75%
HYPE $41.40 -1.40%
AAVE $96.39 -0.24%
SUI $0.9253 -2.27%
XLM $0.1658 -3.35%
ZEC $352.43 -0.85%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.