A supply chain attack affecting GitHub that targeted Coinbase in March has now been identified as originating from a token stolen from a SpotBugs workflow , allowing a malicious actor to compromise multiple projects on GitHub.
See also: GitHub: Updates Advanced Security for more security

The popular static analysis tool SpotBugs was compromised in November 2024, resulting in the breach of Reviewdog, which in turn led to the infection of tj-actions/changed-files.
The supply chain attack, which involved multiple steps, ultimately exposed secrets in 218 repositories, while the latest discoveries showed that the malicious actors were initially trying to compromise projects owned by cryptocurrency exchange Coinbase.
The origin of the attack, which remained unknown until now, was discovered by researchers at Palo Alto Networks' Unit 42, who added an update yesterday to their initial analysis of the incident.
We now know that the supply chain attack began in late November 2024, when a SpotBugs maintainer (SPTBHS_MNTNR) entered his personal access token (PAT) into a CI workflow. On December 6, 2024, an attacker exploited a vulnerable 'pull_request_target' workflow to steal the maintainer's PAT via a malicious pull request from a user account created for this purpose (randolzflow).
See also: Coinbase was the target of GitHub Actions breaches
On March 11, 2025, the attacker used the stolen PAT to invite another fake user (jurkaofavak) to SpotBugs, who promoted a malicious GitHub Actions that exported another PAT belonging to a Reviewdog maintainer (RD_MNTNR) who also had access to SpotBugs.

The stolen PAT had write access to 'reviewdog/action-setup', allowing the attacker to replace the v1 tag with a malicious commit from a fork, affecting all users of v1. This created a backdoor, which was executed when used by 'tj-actions/eslint-changed-files', which was essential for the project.
Using stolen SpotBugs credentials , the attacker replaced the git tags in the repository to point to a malicious commit that would expose secrets from CI runners in the logs, potentially affecting 23,000 GitHub repositories that used this action. However, it was later found that the malicious tj-actions commit only exposed secrets for 218 repositories.
As revealed during subsequent investigations, the attacker customized the malicious commit to target ‘coinbase/agentkit.’ Coinbase’s CI was fetching and executing the infected version on March 14, 2025.
However, no Coinbase secrets were exposed, so the attacker's attempt to gain access to the platform's infrastructure failed. The company was immediately notified of the attempted breach and countered the process.
See also: Valve Steam: Removes game demo that infected systems with info-stealer
A supply chain attack refers to a security attack where attackers aim to compromise an organization through vulnerabilities in one of its suppliers or partners. This strategy exploits the complex nature of the supply chain, which includes many companies that provide various products or services to an organization. Supply chain attacks are particularly dangerous due to the difficulty of detecting them and the widespread damage they can cause.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
