扫码下载
BTC $60,039.28 -5.09%
ETH $1,525.34 -11.69%
BNB $563.29 -5.58%
XRP $1.06 -6.69%
SOL $60.96 -9.85%
TRX $0.3185 -2.87%
DOGE $0.0784 -9.28%
ADA $0.1492 -10.52%
BCH $202.55 -15.29%
LINK $7.09 -9.38%
HYPE $58.14 -7.11%
AAVE $58.38 -15.93%
SUI $0.6686 -9.35%
XLM $0.1913 -2.86%
ZEC $362.38 -5.51%
BTC $60,039.28 -5.09%
ETH $1,525.34 -11.69%
BNB $563.29 -5.58%
XRP $1.06 -6.69%
SOL $60.96 -9.85%
TRX $0.3185 -2.87%
DOGE $0.0784 -9.28%
ADA $0.1492 -10.52%
BCH $202.55 -15.29%
LINK $7.09 -9.38%
HYPE $58.14 -7.11%
AAVE $58.38 -15.93%
SUI $0.6686 -9.35%
XLM $0.1913 -2.86%
ZEC $362.38 -5.51%

慢雾余弦:Coinbase 曾遭 GitHub Actions CI/CD 机制供应链攻击,建议企业自查相关风险

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢雾余弦在 X 平台发文称,利用 GitHub Actions CI/CD 机制供应链攻击 Coinbase,所幸没有继续成功,否则下一个被爆的安全事件就是针对 Coinbase 了。在 GitHub 上的供应链攻击路径:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->窃取 GitHub Personal Access Token(PAT)、云服务有关密钥等。余弦建议,如果企业用到 reviewdog 或 tj-actions,应该进行自查。

app_icon
ChainCatcher 与创新者共建Web3世界