National Cyber Warfare Foundation (NCWF)

Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories' CI CD Secrets Exposed


0 user ratings
2025-03-23 06:57:39
milo
Blue Team (CND)
The supply chain attack involving the GitHub Action "tj-actions/changed-files" started as a highly-targeted attack against one of Coinbase's open-source projects, before evolving into something more widespread in scope.
"The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,"



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/github-supply-chain-breach-coinbase.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.