• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Thursday, July 3, 2025
Techcratic
  • TC
  • AI
    Artificial Intelligence

    EgoDex: Learning Dexterous Manipulation from Large-Scale Egocentric Video

    Artificial Intelligence

    Instruction-Following Pruning for Large Language Models

    Artificial Intelligence

    How to Combine Streamlit, Pandas, and Plotly for Interactive Data Apps

    Artificial Intelligence

    Tailor responsible AI with new safeguard tiers in Amazon Bedrock Guardrails

    Artificial Intelligence

    Automate Data Quality Reports with n8n: From CSV to Professional Analysis

    Artificial Intelligence

    NewDay builds A Generative AI based Customer service Agent Assist with over 90% accuracy

    Artificial Intelligence

    5 Things You Need to Know About Agentic AI

    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

  • App Zone
    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

  • Apple
    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    iPhone expansion, Foxconn India drops Chinese experts, mystery

    Qantas data breach exposes personal details of millions

    Qantas data breach exposes personal details of millions

    July 2, 2025 – iPhone Fold, Apple vs DOJ

    Five new Apple products are launching early this year, here’s what’s coming

    Apple is launching 15+ new products this fall, here’s what’s coming

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    OLED MacBook Pro still expected for 2026 release

    OLED MacBook Pro still expected for 2026 release

    Trump Vietnam deal, costs, AirPods, iPad, Apple Watch, Mac mini

    Trump Vietnam deal, costs, AirPods, iPad, Apple Watch, Mac mini

    iPadOS 26 is perfect for the larger iPad model that’s coming

    Apple’s ‘iPad Fold’ won’t be launching any time soon, per new report

  • Retro Rewind
    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 57 April 1994

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

  • Tech Deals
    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    SABRENT 1TB Rocket Nano XTRM External SSD, USB 3.2 / Thunderbolt 3, Speeds Up to…

    SABRENT 1TB Rocket Nano XTRM External SSD, USB 3.2 / Thunderbolt 3, Speeds Up to…

    MIXAGE 64GB CompactFlash Card UDMA7, 120MB/s Read 45MB/s Write, 85TB TBW, for Canon…

    MIXAGE 64GB CompactFlash Card UDMA7, 120MB/s Read 45MB/s Write, 85TB TBW, for Canon…

    2Pack 3.5Ah Battery Replacement for Hitachi 10.8V-12V Battery BCL1015 BCL1015 BCL1015S…

    2Pack 3.5Ah Battery Replacement for Hitachi 10.8V-12V Battery BCL1015 BCL1015 BCL1015S…

    AC/DC Adapter for G-Technology G-Drive 0G03050 Thunderbolt 4TB G-Tech External Hard…

    AC/DC Adapter for G-Technology G-Drive 0G03050 Thunderbolt 4TB G-Tech External Hard…

  • Tech Eats
    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

  • Tesla
    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Tesla unveils new cheaper, but nerfed ‘Long Range’ Cybertruck

    Tesla confirms Cybertruck sales are down to just ~5,000 units

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    for Tesla Model 3 Floor mat, 3D Custom car mat for Model 3 2017-2025, All Weather Floor…

    for Tesla Model 3 Floor mat, 3D Custom car mat for Model 3 2017-2025, All Weather Floor…

    Metal Tesla Letters Emblem Trunk Logo Decal Tailgate Rear 3m Adhesive Compatible with…

    Metal Tesla Letters Emblem Trunk Logo Decal Tailgate Rear 3m Adhesive Compatible with…

  • UFO
    Unidentified

    Unidentified

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO – Unidentified Flying Object (Drum Cover)

    UFO – Unidentified Flying Object (Drum Cover)

    Mademark x MTV – Cryptid MTV Logo Featuring Bigfoot, UFO, Aliens & Nessie T-Shirt

    Mademark x MTV – Cryptid MTV Logo Featuring Bigfoot, UFO, Aliens & Nessie T-Shirt

    Area 51 Security Costume T-Shirt

    Area 51 Security Costume T-Shirt

    New UFO Sightings Caught on Camera in 2025! (Watch Closely)

    New UFO Sightings Caught on Camera in 2025! (Watch Closely)

    Area 51 Security t-Shirt, Extraterrestrial Being, UFO, Designed and Screen Printed in Los Angeles.

    Area 51 Security t-Shirt, Extraterrestrial Being, UFO, Designed and Screen Printed in Los Angeles.

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    EgoDex: Learning Dexterous Manipulation from Large-Scale Egocentric Video

    Artificial Intelligence

    Instruction-Following Pruning for Large Language Models

    Artificial Intelligence

    How to Combine Streamlit, Pandas, and Plotly for Interactive Data Apps

    Artificial Intelligence

    Tailor responsible AI with new safeguard tiers in Amazon Bedrock Guardrails

    Artificial Intelligence

    Automate Data Quality Reports with n8n: From CSV to Professional Analysis

    Artificial Intelligence

    NewDay builds A Generative AI based Customer service Agent Assist with over 90% accuracy

    Artificial Intelligence

    5 Things You Need to Know About Agentic AI

    Artificial Intelligence

    Normalizing Flows are Capable Generative Models

    Artificial Intelligence

    Update on the AWS DeepRacer Student Portal

  • App Zone
    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Apple: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Launcher Apps for Android: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Card Game Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Medical Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Travel Apps of 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Casual Game Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Food Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Sport Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

    Top 3 Productivity Apps for 2025: Features, Pros, and Cons

  • Apple
    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    M4 iPad Pro, iPad A16, Apple Pencil Pro, AirTag, more 9to5Mac

    iPhone expansion, Foxconn India drops Chinese experts, mystery

    Qantas data breach exposes personal details of millions

    Qantas data breach exposes personal details of millions

    July 2, 2025 – iPhone Fold, Apple vs DOJ

    Five new Apple products are launching early this year, here’s what’s coming

    Apple is launching 15+ new products this fall, here’s what’s coming

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    iOS 26’s new Liquid Glass design looks like a major win for Apple

    OLED MacBook Pro still expected for 2026 release

    OLED MacBook Pro still expected for 2026 release

    Trump Vietnam deal, costs, AirPods, iPad, Apple Watch, Mac mini

    Trump Vietnam deal, costs, AirPods, iPad, Apple Watch, Mac mini

    iPadOS 26 is perfect for the larger iPad model that’s coming

    Apple’s ‘iPad Fold’ won’t be launching any time soon, per new report

  • Retro Rewind
    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Games April 1995

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 57 April 1994

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: Blast from the Past – 35 Iconic Commercials of 1988!

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: PC World Magazine August 1998

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: Computer Shopper Magazine September 1997

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: PC Magazine December 2015

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: EDGE Magazine RETRO #1: The Guide to Classic Videogame Playing and Collecting

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Computer Gaming World Magazine Issue 73 December 1998

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

    Retro Rewind: Electronic Gaming Monthly Magazine Number 55 February 1994

  • Tech Deals
    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    TAGRY Bluetooth Headphones True Wireless Earbuds 60H Playback LED Power Display…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    SABRENT 13 Port High Speed USB 2.0 Hub with Power Adapter and 2 Control Switches…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    ORICO MiniTower 2 Bay RAID Enclosure Compatible NVMe SSD 10Gbps with Expansion Hub…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Blue Yeti USB Mic for Recording and Streaming on PC and Mac with Blue VOCE Effects, 4…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    Lenovo V15 Laptop | 15.6″ FHD Anti-Glare Display | AMD Ryzen 7 7730U | 40GB RAM | 1TB…

    SABRENT 1TB Rocket Nano XTRM External SSD, USB 3.2 / Thunderbolt 3, Speeds Up to…

    SABRENT 1TB Rocket Nano XTRM External SSD, USB 3.2 / Thunderbolt 3, Speeds Up to…

    MIXAGE 64GB CompactFlash Card UDMA7, 120MB/s Read 45MB/s Write, 85TB TBW, for Canon…

    MIXAGE 64GB CompactFlash Card UDMA7, 120MB/s Read 45MB/s Write, 85TB TBW, for Canon…

    2Pack 3.5Ah Battery Replacement for Hitachi 10.8V-12V Battery BCL1015 BCL1015 BCL1015S…

    2Pack 3.5Ah Battery Replacement for Hitachi 10.8V-12V Battery BCL1015 BCL1015 BCL1015S…

    AC/DC Adapter for G-Technology G-Drive 0G03050 Thunderbolt 4TB G-Tech External Hard…

    AC/DC Adapter for G-Technology G-Drive 0G03050 Thunderbolt 4TB G-Tech External Hard…

  • Tech Eats
    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Cheesy Broccoli Rice Mug: 5-Minute Super Comfort Food

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Top 10 Vegetarian Recipes for 2025: Easy and Nutritious Meals for Busy People

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Mug Lasagna: 5-Minute Microwave Meat Lover’s Dream

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon Fried Rice Mug: 5-Minute Microwave Meal

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Bacon & Cheddar Mug Biscuit: 2-Minute Savory Comfort

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Loaded Bacon Cheesy Potato Mug: 5-Minute Comfort Food

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Peanut Butter Banana Mug Muffin: 5-Minute Protein Snack

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Oreo Mug Cake: 2-Minute Cookie & Cake Combo!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

    Tiramisu Mug Cake: Coffee Lover’s Dream in 2 Minutes!

  • Tesla
    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    Femuar Car Trunk Organizer with Large Capacity Waterproof Car Accessories for Women &…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    [Replacement] 4Pcs Roof Rack Cover Cap Rail End Shell for Tesla for Model 3 2017 2018…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Lower Center Console Organizer Tray for Tesla Model Y 2021-2024 & Model 3 2021-2023,…

    Tesla unveils new cheaper, but nerfed ‘Long Range’ Cybertruck

    Tesla confirms Cybertruck sales are down to just ~5,000 units

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    OEDRO Floor Mats Fit for Tesla Model 3 Highland 2024 2025, All Weather Waterproof…

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    Tesla (TSLA) confirms 384,000 deliveries in Q2 2025, right on expectations

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    2025 Upgraded NACS to CCS Adapter, 500A/1000V, 250 kW DC Fast Charging for Ford, Rivian,…

    for Tesla Model 3 Floor mat, 3D Custom car mat for Model 3 2017-2025, All Weather Floor…

    for Tesla Model 3 Floor mat, 3D Custom car mat for Model 3 2017-2025, All Weather Floor…

    Metal Tesla Letters Emblem Trunk Logo Decal Tailgate Rear 3m Adhesive Compatible with…

    Metal Tesla Letters Emblem Trunk Logo Decal Tailgate Rear 3m Adhesive Compatible with…

  • UFO
    Unidentified

    Unidentified

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Paranormal Activity: The Ghost Dimension | official trailer (2015)

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    Interstellar Secrets of Ancient Civilizations | Ancient Aliens

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO Shape LED Dual Purpose Lamp, Portable Adjustable Light Color and Brightness Outdoor Lamp, Motion Sensor Night Lamp, Magnetic Fixation, Rechargeable Flying Saucer Shape Lamp (White)

    UFO – Unidentified Flying Object (Drum Cover)

    UFO – Unidentified Flying Object (Drum Cover)

    Mademark x MTV – Cryptid MTV Logo Featuring Bigfoot, UFO, Aliens & Nessie T-Shirt

    Mademark x MTV – Cryptid MTV Logo Featuring Bigfoot, UFO, Aliens & Nessie T-Shirt

    Area 51 Security Costume T-Shirt

    Area 51 Security Costume T-Shirt

    New UFO Sightings Caught on Camera in 2025! (Watch Closely)

    New UFO Sightings Caught on Camera in 2025! (Watch Closely)

    Area 51 Security t-Shirt, Extraterrestrial Being, UFO, Designed and Screen Printed in Los Angeles.

    Area 51 Security t-Shirt, Extraterrestrial Being, UFO, Designed and Screen Printed in Los Angeles.

No Result
View All Result
Techcratic
No Result
View All Result
Home Cybersecurity

Coinbase Attack Exposes 218 Repositories, Leaks CI/CD Secrets

Cyber Security by Cyber Security
March 23, 2025
in Cybersecurity
Reading Time: 9 mins read
129
A A
0

info@thehackernews.com (The Hacker News)
2025-03-23 01:26:00
thehackernews.com

The supply chain attack involving the GitHub Action “tj-actions/changed-files” started as a highly-targeted attack against one of Coinbase’s open-source projects, before evolving into something more widespread in scope.

“The payload was focused on exploiting the public CI/CD flow of one of their open source projects – agentkit, probably with the purpose of leveraging it for further compromises,” Palo Alto Networks Unit 42 said in a report. “However, the attacker was not able to use Coinbase secrets or publish packages.”

The incident came to light on March 14, 2025, when it was found that “tj-actions/changed-files” was compromised to inject code that leaked sensitive secrets from repositories that ran the workflow. It has been assigned the CVE identifier CVE-2025-30066 (CVSS score: 8.6).

According to Endor Labs, 218 GitHub repositories are estimated to have exposed their secrets due to the supply chain attack, and a majority of the leaked information includes a “few dozen” credentials for DockerHub, npm, and Amazon Web Services (AWS), as well as GitHub install access tokens.

“The initial scale of the supply chain attack sounded scary, considering that tens of thousands of repositories depend on the GitHub Action,” security researcher Henrik Plate said.

“However, drilling down into the workflows, their runs and leaked secrets shows that the actual impact is smaller than anticipated: ‘Only’ 218 repositories leaked secrets, and the majority of those are short-lived GITHUB_TOKENs, which expire once a workflow run is completed.”

Cybersecurity

Since then, it has emerged that the v1 tag of another GitHub Action called “reviewdog/action-setup,” which “tj-actions/changed-files” relies on as a dependency via “tj-actions/eslint-changed-files,” was also compromised in the lead up to the tj-actions incident with a similar payload. The breach of “reviewdog/action-setup” is being tracked as CVE-2025-30154 (CVSS score: 8.6).

The exploitation of CVE-2025-30154 is said to have enabled the unidentified threat actor to obtain a personal access token (PAT) associated with “tj-actions/changed-files,” thereby allowing them to modify the repository and push the malicious code, in turn impacting every single GitHub repository that depended on the action.

“When the tj-actions/eslint-changed-files action was executed, the tj-actions/changed-files CI runner’s secrets were leaked, allowing the attackers to steal the credentials used in the runner, including a Personal Access Token (PAT) belonging to the tj-bot-actions GitHub user account,” Unit 42 researchers Omer Gil, Aviad Hahami, Asi Greenholts, and Yaron Avital said.

It’s currently suspected that the attacker managed to somehow gain access to a token with write access to the reviewdog organization in order to make the rogue alterations. That said, the manner in which this token may have been acquired remains unknown at this stage.

Furthermore, the malicious commits to “reviewdog/action-setup” is said to have been carried out by first forking the corresponding repository, committing changes to it, and then creating a fork pull request to the original repository and ultimately introducing arbitrary commits – a scenario called a dangling commit.

“The attacker took significant measures to conceal their tracks using various techniques, such as leveraging dangling commits, creating multiple temporary GitHub user accounts, and obfuscating their activities in workflow logs (especially in the initial Coinbase attack),” Gil, Senior Research Manager at Palo Alto Networks, told The Hacker News. “These findings indicate that the attacker is highly skilled and has a deep understanding of CI/CD security threats and attack tactics.”

Unit 42 theorized that the user account behind the fork pull request “iLrmKCu86tjwp8” may have been hidden from public view after the attacker switched from a legitimate email address provided during registration to a disposable (or anonymous) email in violation of GitHub’s policy.

This could have caused all the interactions and actions performed by the user to be concealed. However, when reached for comment, GitHub did not confirm or deny the hypothesis, but said it’s actively reviewing the situation and taking action as necessary.

“There is currently no evidence to suggest a compromise of GitHub or its systems. The projects highlighted are user-maintained open-source projects,” a GitHub spokesperson told The Hacker News.

“GitHub continues to review and take action on user reports related to repository contents, including malware and other malicious attacks, in accordance with GitHub’s Acceptable Use Policies. Users should always review GitHub Actions or any other package that they are using in their code before they update to new versions. That remains true here as in all other instances of using third party code.”

A deeper search for GitHub forks of tj-actions/changed-files has led to the discovery of two other accounts “2ft2dKo28UazTZ” and “mmvojwip,” both of which have since been deleted from the platform. Both the accounts have also been found to create forks of Coinbase-related repositories such as onchainkit, agentkit, and x402.

Further examination has uncovered that the accounts modified the “changelog.yml” file in the agentkit repository using a fork pull request to point to a malicious version of “tj-actions/changed-files” published earlier using the PAT.

The attacker is believed to have obtained a GitHub token with write permissions to the agentkit repository – in turn facilitated by the execution of the tj-actions/changed-files GitHub Actions – so as to make the unauthorized changes.

Cybersecurity

Another important aspect worth highlighting is the difference in payloads used in both the cases, indicating attempts on part of the attacker to stay under the radar.

“The attacker used different payloads at different stages of the attack. For example, in the widespread attack, the attacker dumped the runner’s memory and printed secrets stored as environment variables to the workflow’s log, regardless of which workflow was running,” Gil said.

“However, when targeting Coinbase, the attacker specifically fetched the GITHUB_TOKEN and ensured that the payload would only execute if the repository belonged to Coinbase.”

It’s currently not known what the end goal of the campaign was, it’s “strongly” suspected that the intent was financial gain, likely attempting to conduct cryptocurrency theft, given the hyper-specific targeting of Coinbase, Gil pointed out. As of March 19, 2025, the cryptocurrency exchange has remediated the attack.

It’s also not clear what prompted the attacker to switch gears, turning what was an initially targeted attack turned into a large-scale and less stealthy campaign.

“One hypothesis is that after realizing they could not leverage their token to poison the Coinbase repository — and upon learning that Coinbase had detected and mitigated the attack — the attacker feared losing access to the tj-actions/changed-files action,” Gil said.

“Since compromising this action could provide access to many other projects, they may have decided to act quickly. This could explain why they launched the widespread attack just 20 minutes after Coinbase mitigated the exposure on their end despite the increased risk of detection.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source Link


Upgrade your audio game with the Logitech for Creators Blue Yeti USB Microphone. With over 33,730 ratings and an impressive 4.6 out of 5 stars, it’s no wonder this is an Amazon’s Choice product. Recently, 5K+ units were purchased in the past month.

Available in five stunning colors: Teal, Silver, Pink Dawn, Midnight Blue, and Blackout, this microphone is perfect for creators looking to produce exceptional audio. Priced at only $84.99, it’s a deal you can’t afford to miss.

Elevate your recordings with clear broadcast-quality sound and explore your creativity with enhanced effects, advanced modulation, and HD audio samples. Order now for just $84.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Help Power Techcratic’s Future – Scan To Support

If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.

As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!

BITCOIN

Bitcoin Logo

Bitcoin QR Code

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Scan the QR code with your crypto wallet app

DOGECOIN

Dogecoin Logo

Dogecoin QR Code

D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA

Scan the QR code with your crypto wallet app

ETHEREUM

Ethereum Logo

Ethereum QR Code

0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a

Scan the QR code with your crypto wallet app

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Cybersecurity
Share161Share28ShareShare4ShareTweet101
Previous Post

Tether Ranks Seventh Among Top US Treasuries Buyers in 2024

Next Post

The Legend Of Zelda Ocarina Of Time 3D Nintendo 3DS Walkthrough Part 21 Boss Barinade

Cyber Security

Cyber Security

Explore the critical updates and expert insights in cybersecurity. Stay protected and informed with the latest trends, threats, and solutions in the world of digital security. Find the latest articles here at Techcratic.

Related Posts

Cybersecurity
Cybersecurity

Malware sharing, data wiping and exploits

July 2, 2025
1.3k
Cybersecurity
Cybersecurity

Google Patches Critical Zero-Day Flaw in Chrome’s V8 Engine After Active Exploitation

July 1, 2025
1.3k
Cybersecurity
Cybersecurity

Microsoft Removes Password Management from Authenticator App Starting August 2025

July 1, 2025
1.3k
Cybersecurity
Cybersecurity

Business Case for Agentic AI SOC Analysts

June 27, 2025
1.3k
Cybersecurity
Cybersecurity

MOVEit Transfer Faces Increased Threats as Scanning Surges and CVE Flaws Are Targeted

June 27, 2025
1.3k
Cybersecurity
Cybersecurity

Critical Open VSX Registry Flaw Exposes Millions of Developers to Supply Chain Attacks

June 26, 2025
1.3k
Cybersecurity
Cybersecurity

Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access

June 26, 2025
1.3k
Cybersecurity
Cybersecurity

WhatsApp Adds AI-Powered Message Summaries for Faster Chat Previews

June 26, 2025
1.3k
Load More
Next Post
The Legend Of Zelda Ocarina Of Time 3D Nintendo 3DS Walkthrough Part 21 Boss Barinade

The Legend Of Zelda Ocarina Of Time 3D Nintendo 3DS Walkthrough Part 21 Boss Barinade

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Forbes
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Gaming
  • I Like Cats ™
  • I Like Dogs ™
  • MacRumors
  • Macworld
  • Tech Deals
  • Techcratic ™
  • Techs Got To Eat ™
  • Tesla
  • UFO
  • Wired