扫码下载
BTC $77,537.03 -0.88%
ETH $2,322.19 -2.88%
BNB $632.85 -1.41%
XRP $1.41 -2.67%
SOL $85.66 -2.98%
TRX $0.3281 -1.95%
DOGE $0.0959 -2.15%
ADA $0.2467 -3.42%
BCH $453.90 -2.76%
LINK $9.22 -3.08%
HYPE $41.11 +0.57%
AAVE $91.99 -1.27%
SUI $0.9399 -3.22%
XLM $0.1755 -2.28%
ZEC $317.83 -0.22%
BTC $77,537.03 -0.88%
ETH $2,322.19 -2.88%
BNB $632.85 -1.41%
XRP $1.41 -2.67%
SOL $85.66 -2.98%
TRX $0.3281 -1.95%
DOGE $0.0959 -2.15%
ADA $0.2467 -3.42%
BCH $453.90 -2.76%
LINK $9.22 -3.08%
HYPE $41.11 +0.57%
AAVE $91.99 -1.27%
SUI $0.9399 -3.22%
XLM $0.1755 -2.28%
ZEC $317.83 -0.22%

慢雾余弦:Coinbase 曾遭 GitHub Actions CI/CD 机制供应链攻击,建议企业自查相关风险

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢雾余弦在 X 平台发文称,利用 GitHub Actions CI/CD 机制供应链攻击 Coinbase,所幸没有继续成功,否则下一个被爆的安全事件就是针对 Coinbase 了。在 GitHub 上的供应链攻击路径:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->窃取 GitHub Personal Access Token(PAT)、云服务有关密钥等。余弦建议,如果企业用到 reviewdog 或 tj-actions,应该进行自查。

app_icon
ChainCatcher 与创新者共建Web3世界