Skip to content

Commit 0ee12d0

Browse files
authored
Update software-supply-chain-attacks-crypto.md
1 parent 51dae3d commit 0ee12d0

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

software-supply-chain-attacks-crypto.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,14 @@ The Socket Research Team identified a malicious PyPI package named 'set-utils' t
182182
Sources:
183183
- <https://socket.dev/blog/new-pypi-malware-exfiltrates-ethereum-private-keys>
184184

185+
### 20. changed-files attack, suspected to target Coinbase
186+
187+
On March 14, 2025, an attack on Github Action tj-actions/changed-files was detected by StepSecurity's researchers, who reported the incident to the maintainers of the tj-actions organization. Unit 42 collected evidence that Coinbase was the target, but the attack was not successful.
188+
189+
Sources:
190+
191+
* <https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised>
192+
* <https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/>
185193

186194
## Hardware supply chain attacks
187195

0 commit comments

Comments
 (0)