Scan to download
BTC $67,323.08 +0.74%
ETH $2,055.55 +0.35%
BNB $591.91 +0.68%
XRP $1.31 -0.41%
SOL $80.93 +0.95%
TRX $0.3171 +0.81%
DOGE $0.0922 +0.21%
ADA $0.2473 -0.55%
BCH $442.13 +0.05%
LINK $8.69 +0.17%
HYPE $35.99 +0.91%
AAVE $94.76 +0.47%
SUI $0.8702 -0.43%
XLM $0.1613 -1.22%
ZEC $251.86 +7.15%
BTC $67,323.08 +0.74%
ETH $2,055.55 +0.35%
BNB $591.91 +0.68%
XRP $1.31 -0.41%
SOL $80.93 +0.95%
TRX $0.3171 +0.81%
DOGE $0.0922 +0.21%
ADA $0.2473 -0.55%
BCH $442.13 +0.05%
LINK $8.69 +0.17%
HYPE $35.99 +0.91%
AAVE $94.76 +0.47%
SUI $0.8702 -0.43%
XLM $0.1613 -1.22%
ZEC $251.86 +7.15%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.