The 443 - Security Simplified Podcast
The 443 - Security Simplified
Secplicity
Github Actions Supply Chain Attacks - episode of The 443 - Security Simplified podcast

Github Actions Supply Chain Attacks

42 minutes Posted Mar 31, 2025 at 3:06 pm.
0:00
42:12
Download MP3
Show notes
This week, we discuss a recent cascading supply chain attack involving multiple Github actions workflows that nearly succeeded in compromising a popular Coinbase application. Before that, we discuss a novel way to download malware onto an endpoint by abusing a web browser's caching feature. Additionally, we cover an FBI alert on file converter malware scams.