Slow Mist Cosine: Coinbase has been attacked by the GitHub Actions CI/CD mechanism supply chain, and it is recommended that companies check their own risks
2025-03-23 08:08:31
On March 23rd, Slow Mist founder Cosine posted on social media, "Using the GitHub Actions CI/CD mechanism to attack Coinbase in the supply chain, fortunately it did not continue to succeed, otherwise the next security incident to be exposed would be against Coinbase. Supply chain attack path on GitHub: reviewdog/action-settings - > tj-actions/changed-files - > coinbase/agentkit - > steal GitHub personal access tokens (PAT), Cloud as a Service related keys, etc. Cosine suggests that if enterprises use reviewdog or tj-actions, they should conduct self-examination."
Disclaimer:
1. The information provided does not constitute investment advice. Investors should make independent decisions and bear all risks themselves.
2. The copyright of this content belongs to the original author. The views expressed herein are solely those of the author and do not represent the stance or position of this website.
Previous article:
慢雾余弦:Coinbase曾遭GitHub Actions CI/CD机制供应链攻击,建议企业自查相关风险Next article:
研究:阿联酋对加密货币的采用处于领先地位