Scan to download
BTC $60,923.71 +0.73%
ETH $1,562.47 -2.28%
BNB $576.08 -1.13%
XRP $1.10 -0.68%
SOL $62.70 -3.35%
TRX $0.3204 -1.25%
DOGE $0.0820 -1.27%
ADA $0.1601 -0.72%
BCH $218.30 -0.30%
LINK $7.41 -0.10%
HYPE $58.60 -6.42%
AAVE $61.01 -2.38%
SUI $0.7233 +2.59%
XLM $0.2018 +5.71%
ZEC $352.25 +5.25%
BTC $60,923.71 +0.73%
ETH $1,562.47 -2.28%
BNB $576.08 -1.13%
XRP $1.10 -0.68%
SOL $62.70 -3.35%
TRX $0.3204 -1.25%
DOGE $0.0820 -1.27%
ADA $0.1601 -0.72%
BCH $218.30 -0.30%
LINK $7.41 -0.10%
HYPE $58.60 -6.42%
AAVE $61.01 -2.38%
SUI $0.7233 +2.59%
XLM $0.2018 +5.71%
ZEC $352.25 +5.25%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.