Scan to download
BTC $74,926.70 +0.45%
ETH $2,344.56 -0.27%
BNB $633.57 +1.88%
XRP $1.44 +3.00%
SOL $88.88 +4.86%
TRX $0.3265 +0.11%
DOGE $0.0992 +4.69%
ADA $0.2584 +5.64%
BCH $453.67 +3.09%
LINK $9.51 +3.03%
HYPE $43.86 -0.84%
AAVE $115.22 +8.92%
SUI $1.00 +4.65%
XLM $0.1684 +6.73%
ZEC $341.89 -0.53%
BTC $74,926.70 +0.45%
ETH $2,344.56 -0.27%
BNB $633.57 +1.88%
XRP $1.44 +3.00%
SOL $88.88 +4.86%
TRX $0.3265 +0.11%
DOGE $0.0992 +4.69%
ADA $0.2584 +5.64%
BCH $453.67 +3.09%
LINK $9.51 +3.03%
HYPE $43.86 -0.84%
AAVE $115.22 +8.92%
SUI $1.00 +4.65%
XLM $0.1684 +6.73%
ZEC $341.89 -0.53%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.