SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack

Post by Shane1145 »

The cascading supply chain attack that initially targeted Coinbase before becoming more widespread to single out users of the "tj-actions/changed-files" GitHub Action has been traced further back to the theft of a personal access token (PAT) related to SpotBugs.

"The attackers obtained initial access by taking advantage of the GitHub Actions workflow of SpotBugs, a popular open-source tool for static analysis of bugs in code," Palo Alto Networks Unit 42 said in an update this week. "This enabled the attackers to move laterally between SpotBugs repositories, until obtaining access to reviewdog."


https://thehackernews.com/2025/04/spotb ... ified.html
Post Reply