掃碼下載
BTC $62,815.50 +2.49%
ETH $1,639.51 +3.51%
BNB $597.32 +2.63%
XRP $1.13 +4.33%
SOL $65.58 +3.58%
TRX $0.3282 +2.71%
DOGE $0.0854 +3.82%
ADA $0.1648 +3.49%
BCH $226.17 +0.83%
LINK $7.77 +4.44%
HYPE $60.02 -0.24%
AAVE $63.95 +3.12%
SUI $0.7563 +6.27%
XLM $0.2064 +0.90%
ZEC $398.33 +6.85%
BTC $62,815.50 +2.49%
ETH $1,639.51 +3.51%
BNB $597.32 +2.63%
XRP $1.13 +4.33%
SOL $65.58 +3.58%
TRX $0.3282 +2.71%
DOGE $0.0854 +3.82%
ADA $0.1648 +3.49%
BCH $226.17 +0.83%
LINK $7.77 +4.44%
HYPE $60.02 -0.24%
AAVE $63.95 +3.12%
SUI $0.7563 +6.27%
XLM $0.2064 +0.90%
ZEC $398.33 +6.85%

慢霧餘弦:Coinbase 曾遭 GitHub Actions CI/CD 機制供應鏈攻擊,建議企業自查相關風險

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢霧餘弦在 X 平台發文稱,利用 GitHub Actions CI/CD 機制供應鏈攻擊 Coinbase,所幸沒有繼續成功,否則下一個被爆的安全事件就是針對 Coinbase 了。在 GitHub 上的供應鏈攻擊路徑:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->竊取 GitHub Personal Access Token(PAT)、雲服務有關密鑰等。餘弦建議,如果企業用到 reviewdog 或 tj-actions,應該進行自查。

app_icon
ChainCatcher 與創新者共建Web3世界