Coinbase Initially Targeted in GitHub Actions Supply Chain Attack; 218 Repositories’ CI/CD Secrets Exposed
,
The supply chain attack involving the GitHub Action « tj-actions/changed-files » started as a highly-targeted attack against one of Coinbase’s open-source projects, before evolving into something more widespread in scope.
« The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises, »
« The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises, »
,
The supply chain attack involving the GitHub Action « tj-actions/changed-files » started as a highly-targeted attack against one of Coinbase’s open-source projects, before evolving into something more widespread in scope.
« The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises, »
« The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises, »
, ,
https://thehackernews.com/2025/03/github-supply-chain-breach-coinbase.html