Showing 0 Items
Malicious 2773 beta versions of @joyfill/components and @joyfill/layouts carry an obfuscated remote access trojan and credential stealer that run on import. Here is how it works and how to check if you are affected.
A hijacked maintainer account published mrmustard 0.7.4 to PyPI with a credential stealer that runs on import, exfiltrating SSH keys, AWS, and Kubernetes credentials from developer and research machines. Full analysis, IOCs, and response steps.
After growing ARR more than 5x in 2024 and again in 2025, StepSecurity is on pace for its biggest year yet in 2026. Here is what is driving it, and why the software supply chain security market is inflecting.
StepSecurity now shows which GitHub Actions secrets are actually used, which workflows use them, and which can be replaced with OIDC.
Malicious versions of git_credential_manager, Dendreo, and a fastlane plugin were published to RubyGems. They fetch a second stage from a Forgejo command and control host, skip CI to target developer machines, and install a persistent daemon. StepSecurity ran them under Harden-Runner to capture the full kill chain.
Harden-Runner secures third-party GitHub Actions runners. Bitrise macOS runners join Blacksmith, Depot, Namespace, and Warp Build with v2.20.0
Harden-Runner v2.20.0 extends egress block mode to macOS and Windows GitHub-hosted runners, so you can stop secret exfiltration on every OS your pipelines run on, not just observe it.
Device Policy lets security teams allow-list VS Code extensions and enforce it fleet-wide through Intune, Jamf, Kandji, or the DMG agent. No MDM required.