The supply chain attack involving the GitHub Action "tj-actions/changed-files" started as a highly-targeted attack against one of Coinbase's open-source projects, before evolving into something more widespread in scope. "The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,"
![]()
source https://thehackernews.com/2025/03/github-supply-chain-breach-coinbase.html
source https://thehackernews.com/2025/03/github-supply-chain-breach-coinbase.html