The GitHub Action “tj-actions/changed-files” was at the center of the supply chain breach, commencing as a precise strike against one of Coinbase’s public projects before expanding its impact.
“The attack targeted the exposed CI/CD pipeline of their open source project – agentkit, likely intending to use it as a foothold for additional intrusions,”
“The attack targeted the exposed CI/CD pipeline of their open source project – agentkit, likely intending to use it as a foothold for additional intrusions,”
