Risk Warning: Beware of illegal fundraising in the name of 'virtual currency' and 'blockchain'. — Five departments including the Banking and Insurance Regulatory Commission
Information
Discover
Search
Login
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt
BTC
ETH
HTX
SOL
BNB
View Market
SlowMist Cosine: Coinbase became the target of the GitHub Actions CI/CD mechanism supply chain attack, but fortunately it did not succeed
2025-03-23 07:59:12

Odaily News SlowMist Yuxian posted on the X platform that it used the GitHub Actions CI/CD mechanism supply chain to attack Coinbase, but fortunately it did not continue to succeed, otherwise the next security incident would be against Coinbase. The supply chain attack path on GitHub: reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit -> steal GitHub Personal Access Token (PAT), cloud service-related keys, etc. Yuxian suggested that if an enterprise uses reviewdog or tj-actions, it should conduct a self-examination.