扫码下载
BTC $61,710.22 +1.64%
ETH $1,625.14 +4.29%
BNB $593.02 +3.19%
XRP $1.12 +4.00%
SOL $64.52 +4.28%
TRX $0.3256 +0.99%
DOGE $0.0839 +3.71%
ADA $0.1601 +1.87%
BCH $222.27 +3.54%
LINK $7.67 +4.59%
HYPE $58.34 +2.72%
AAVE $62.15 +2.71%
SUI $0.7391 +4.42%
XLM $0.2019 -1.65%
ZEC $419.72 +19.25%
BTC $61,710.22 +1.64%
ETH $1,625.14 +4.29%
BNB $593.02 +3.19%
XRP $1.12 +4.00%
SOL $64.52 +4.28%
TRX $0.3256 +0.99%
DOGE $0.0839 +3.71%
ADA $0.1601 +1.87%
BCH $222.27 +3.54%
LINK $7.67 +4.59%
HYPE $58.34 +2.72%
AAVE $62.15 +2.71%
SUI $0.7391 +4.42%
XLM $0.2019 -1.65%
ZEC $419.72 +19.25%

慢雾余弦:Coinbase 曾遭 GitHub Actions CI/CD 机制供应链攻击,建议企业自查相关风险

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢雾余弦在 X 平台发文称,利用 GitHub Actions CI/CD 机制供应链攻击 Coinbase,所幸没有继续成功,否则下一个被爆的安全事件就是针对 Coinbase 了。在 GitHub 上的供应链攻击路径:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->窃取 GitHub Personal Access Token(PAT)、云服务有关密钥等。余弦建议,如果企业用到 reviewdog 或 tj-actions,应该进行自查。

app_icon
ChainCatcher 与创新者共建Web3世界