Forwarded from The Hacker News
👀 $0 GitHub Action ➔ $B security nightmare.
In Nov 2024, a SpotBugs maintainer accidentally leaked a GitHub access token.
⚡ Attackers exploited it—moving from SpotBugs ➔ reviewdog ➔ poisoning tj-actions/changed-files—before striking Coinbase in March 2025.
➡️ Details here: https://thehackernews.com/2025/04/spotbugs-access-token-theft-identified.html
In Nov 2024, a SpotBugs maintainer accidentally leaked a GitHub access token.
⚡ Attackers exploited it—moving from SpotBugs ➔ reviewdog ➔ poisoning tj-actions/changed-files—before striking Coinbase in March 2025.
➡️ Details here: https://thehackernews.com/2025/04/spotbugs-access-token-theft-identified.html