BTC $65,065.19 -0.88%
ETH $1,886.27 -1.92%
BNB $567.82 -0.23%
XRP $1.11 -2.17%
SOL $75.56 -2.44%
TRX $0.3309 +1.11%
DOGE $0.0699 -3.13%
ADA $0.1671 -3.70%
BCH $211.35 -2.31%
LINK $8.52 -1.16%
HYPE $58.77 -0.66%
AAVE $96.13 -1.16%
SUI $0.7360 -4.39%
XLM $0.1831 -0.79%
ZEC $506.15 -1.85%
BTC $65,065.19 -0.88%
ETH $1,886.27 -1.92%
BNB $567.82 -0.23%
XRP $1.11 -2.17%
SOL $75.56 -2.44%
TRX $0.3309 +1.11%
DOGE $0.0699 -3.13%
ADA $0.1671 -3.70%
BCH $211.35 -2.31%
LINK $8.52 -1.16%
HYPE $58.77 -0.66%
AAVE $96.13 -1.16%
SUI $0.7360 -4.39%
XLM $0.1831 -0.79%
ZEC $506.15 -1.85%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55
Collection

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.