SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack
The theft of a personal access token (PAT) connected to SpotBugs has been linked to the cascading supply chain attack that first targeted Coinbase before spreading to target users of the "tj-actions/changed-files GitHub Action."
Palo Alto Networks Unit 42 claimed in an update this week that the attackers gained early access by exploiting the GitHub Actions process of SpotBugs, a well-known open-source application for static analysis of code issues. In order to gain access to reviewdog, the attackers were able to traverse laterally between SpotBugs repositories.
Although the attack against Coinbase did not occur until March 2025, there is evidence that the harmful behavior started as early as November 2024 read more about SpotBugs Access Token Theft Identified as Root Cause of GitHub...

