Scan to download
BTC $79,137.41 -2.63%
ETH $2,220.60 -3.08%
BNB $673.60 -0.82%
XRP $1.43 -4.87%
SOL $89.29 -3.43%
TRX $0.3515 -0.99%
DOGE $0.1131 -1.94%
ADA $0.2610 -4.15%
BCH $424.72 -2.79%
LINK $10.05 -5.04%
HYPE $44.50 +1.55%
AAVE $92.67 -6.66%
SUI $1.09 -8.00%
XLM $0.1545 -6.08%
ZEC $515.29 -3.89%
BTC $79,137.41 -2.63%
ETH $2,220.60 -3.08%
BNB $673.60 -0.82%
XRP $1.43 -4.87%
SOL $89.29 -3.43%
TRX $0.3515 -0.99%
DOGE $0.1131 -1.94%
ADA $0.2610 -4.15%
BCH $424.72 -2.79%
LINK $10.05 -5.04%
HYPE $44.50 +1.55%
AAVE $92.67 -6.66%
SUI $1.09 -8.00%
XLM $0.1545 -6.08%
ZEC $515.29 -3.89%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.