BTC $79,352.74 -0.80%
ETH $2,501.34 -0.25%
BNB $742.48 -1.14%
XRP $1.40 -0.57%
SOL $104.06 -1.67%
TRX $0.3350 -0.03%
DOGE $0.0910 +0.90%
ADA $0.2220 +0.33%
BCH $261.58 +1.97%
LINK $12.74 -1.93%
HYPE $85.12 -2.22%
AAVE $132.10 -1.30%
SUI $0.8340 +4.53%
XLM $0.1927 +3.05%
ZEC $1,144.43 -3.51%
BTC $79,352.74 -0.80%
ETH $2,501.34 -0.25%
BNB $742.48 -1.14%
XRP $1.40 -0.57%
SOL $104.06 -1.67%
TRX $0.3350 -0.03%
DOGE $0.0910 +0.90%
ADA $0.2220 +0.33%
BCH $261.58 +1.97%
LINK $12.74 -1.93%
HYPE $85.12 -2.22%
AAVE $132.10 -1.30%
SUI $0.8340 +4.53%
XLM $0.1927 +3.05%
ZEC $1,144.43 -3.51%

Slow Fog: Coinbase has suffered a supply chain attack on its GitHub Actions CI/CD mechanism, advising companies to self-check related risks

2025-03-23 16:07:55

ChainCatcher message, Slow Mist Cosine posted on platform X stating that a supply chain attack on Coinbase was carried out using the GitHub Actions CI/CD mechanism. Fortunately, it did not continue successfully; otherwise, the next security incident exposed would have been against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> stealing GitHub Personal Access Token (PAT), cloud service-related keys, etc. Cosine suggests that if companies use reviewdog or tj-actions, they should conduct a self-check.

app_icon
ChainCatcher Building the Web3 world with innovations.