• News/
  • https://www.bleepingcomputer.com/news/security/recent-github-supply-chain-attack-traced-to-leaked-spotbugs-token/

Recent GitHub supply chain attack traced to leaked SpotBugs token

BleepingComputer
·
Bill Toulas
·
Published Apr 3, 2025
·
Updated

A cascading supply chain attack on GitHub that targeted Coinbase in March has now been traced back to a single token stolen from a SpotBugs workflow, which allowed a threat actor to compromise multiple GitHub projects. The popular static analysis tool SpotBugs was breached in November 2024, leading to the compromise of Reviewdog, which subsequently led to the infection of tj-actions/changed-files. The multi-step supply chain attack eventually exposed secrets in 218 repositories, while the latest findings showed that the threat actors were initially attempting to breach projects belonging to the cryptocurrency exchange Coinbase. The start of the attack, which has remained unknown so far, was discovered by Palo Alto Networks' Unit 42 researchers who added an update yesterday on their original analysis of the incident. We now know that the supply chain attack started in late November 2024 when a SpotBugs maintainer (SPTBHS_MNTNR) added their Personal Access Token (PAT) into a CI workflow. On December 6, 2024, an attacker exploited a vulnerable 'pull_request_target' workflow to steal the maintainer's PAT via a malicious pull request from a throwaway user account (randolzflow). On March 11, 2025, the attacker used the stolen PAT to invite another dummy user (jurkaofavak) into SpotBugs, who pushed a malicious GitHub Actions workflow that exfiltrated another PAT belonging to a Reviewdog maintainer (RD_MNTNR) who also had access to SpotBugs. The stolen PAT had write access to 'revie...

Read full article

Affected Software

8 affected components
SpotBugs SpotBugs
reviewdog Reviewdog
tj-actions changed-files
tj-actions eslint-changed-files
Coinbase agentkit
SpotBugs SpotBugs
reviewdog Reviewdog
tj-actions changed-files
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main cause of the GitHub supply chain attack?

The attack was traced back to a leaked SpotBugs token that allowed unauthorized access.

2

Which major company was specifically targeted in this supply chain attack?

Coinbase was specifically targeted during the cascading supply chain attack.

3

What security implications does the article highlight regarding token management?

The article emphasizes the importance of securely managing and protecting access tokens to prevent such attacks.

4

Which software products are mentioned as being affected by the leaked SpotBugs token?

The affected software products include SpotBugs, Reviewdog, and tj-actions projects.

5

How does this incident illustrate the risks of supply chain vulnerabilities?

This incident highlights how a single compromised token can lead to widespread access and multiple project compromises in a supply chain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203