BTC $62,983.57 +0.03%
ETH $1,877.43 -0.26%
BNB $606.36 -0.13%
XRP $1.00 -0.01%
SOL $75.34 +0.02%
TRX $0.3307 -0.53%
DOGE $0.0695 -0.69%
ADA $0.1763 -1.82%
BCH $203.49 -0.95%
LINK $9.47 +2.63%
HYPE $57.02 +1.17%
AAVE $86.08 -0.23%
SUI $0.6751 -0.87%
XLM $0.1570 -0.78%
ZEC $485.84 -2.11%
BTC $62,983.57 +0.03%
ETH $1,877.43 -0.26%
BNB $606.36 -0.13%
XRP $1.00 -0.01%
SOL $75.34 +0.02%
TRX $0.3307 -0.53%
DOGE $0.0695 -0.69%
ADA $0.1763 -1.82%
BCH $203.49 -0.95%
LINK $9.47 +2.63%
HYPE $57.02 +1.17%
AAVE $86.08 -0.23%
SUI $0.6751 -0.87%
XLM $0.1570 -0.78%
ZEC $485.84 -2.11%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.