troupe allegedly hacked as reported by BleepingComputer with details: a cascading provide chain attack on GitHub that targeted Coinbase in march has now been traced backrest to a single token stolen from a SpotBugs workflow, which allowed a threat actor to compromise multiple GitHub projects.