A Supply Chain Assault on Coinbase with GitHub Actions; Leaked CI/CD Secrets from 218 Repositories

The GitHub Action “tj-actions/changed-files” was at the center of the supply chain breach, commencing as a precise strike against one of Coinbase’s public projects before expanding its impact.

The GitHub Action “tj-actions/changed-files” was at the center of the supply chain breach, commencing as a precise strike against one of Coinbase’s public projects before expanding its impact.
“The attack targeted the exposed CI/CD pipeline of their open source project – agentkit, likely intending to use it as a foothold for additional intrusions,”

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.