Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

Team PCP CI/CD secrets heist: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations in five days, per the CloudSEK disclosure

Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's research team has tracked this threat actor across the Trivy, telnyx, and LiteLLM compromises. Here is how the campaign works, why CI/CD pipelines are the target, and the layered controls that stop it.

Control Which Package Registries Your CI Jobs and Developer Machines Use

Two StepSecurity controls show every CI job and developer machine that still installs from public registries. Once you can see them, you can block public registries in CI and centrally set the registry configuration on every developer machine.

ChainDrop npm worm blast radius: 444 packages poisoned, 2,212 malicious versions, 450M+ weekly downloads hit, 14+ orgs compromised, starting with keyv@6.0.0

ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

A self-propagating npm worm we call ChainDrop poisoned 444 packages and 2,212 versions in under four hours, starting with keyv@6.0.0. Full payload analysis, the affected package list, IOCs, and what to do now.

An AI agent published a malicious package to PyPI

Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It

Anthropic disclosed that a Claude model published a malicious package to PyPI during a cybersecurity evaluation. It ran on 15 real systems within an hour, including a security company's malware scanner. StepSecurity is not that company, and Anthropic confirmed it to us in writing. Here is what happened and what it means for supply chain defense.

Dev Machine Guard Now Inventories AI Agent Skills on Developer Machines

Dev Machine Guard now inventories AI agent skills across your developer fleet. See every skill installed for Claude Code, Codex, GitHub Copilot, and other agents, flag skills with executable code, hooks, or shell commands, trace provenance, and detect version drift.

Obfuscated remote access trojan shipped in two Joyfill npm packages

Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan

Malicious 2773 beta versions of @joyfill/components and @joyfill/layouts carry an obfuscated remote access trojan and credential stealer that run on import. Here is how it works and how to check if you are affected.

mrmustard 0.7.4 compromised PyPI package, StepSecurity threat intelligence analysis

Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

A hijacked maintainer account published mrmustard 0.7.4 to PyPI with a credential stealer that runs on import, exfiltrating SSH keys, AWS, and Kubernetes credentials from developer and research machines. Full analysis, IOCs, and response steps.

2026 Mid-Year Update: On Pace for Our Biggest Year Yet

After growing ARR more than 5x in 2024 and again in 2025, StepSecurity is on pace for its biggest year yet in 2026. Here is what is driving it, and why the software supply chain security market is inflecting.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.