BTC $79,198.47 -0.87%
ETH $2,492.82 -0.52%
BNB $739.50 -1.78%
XRP $1.40 -1.91%
SOL $103.95 -2.08%
TRX $0.3346 -0.39%
DOGE $0.0905 -0.00%
ADA $0.2212 -0.32%
BCH $261.18 +0.75%
LINK $12.77 -1.40%
HYPE $85.28 -3.02%
AAVE $132.52 -1.61%
SUI $0.8300 +2.19%
XLM $0.1931 +3.78%
ZEC $1,154.81 -6.34%
BTC $79,198.47 -0.87%
ETH $2,492.82 -0.52%
BNB $739.50 -1.78%
XRP $1.40 -1.91%
SOL $103.95 -2.08%
TRX $0.3346 -0.39%
DOGE $0.0905 -0.00%
ADA $0.2212 -0.32%
BCH $261.18 +0.75%
LINK $12.77 -1.40%
HYPE $85.28 -3.02%
AAVE $132.52 -1.61%
SUI $0.8300 +2.19%
XLM $0.1931 +3.78%
ZEC $1,154.81 -6.34%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.