Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

mrmustard 0.7.4 compromised PyPI package, StepSecurity threat intelligence analysis

Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials

A hijacked maintainer account published mrmustard 0.7.4 to PyPI with a credential stealer that runs on import, exfiltrating SSH keys, AWS, and Kubernetes credentials from developer and research machines. Full analysis, IOCs, and response steps.

2026 Mid-Year Update: On Pace for Our Biggest Year Yet

After growing ARR more than 5x in 2024 and again in 2025, StepSecurity is on pace for its biggest year yet in 2026. Here is what is driving it, and why the software supply chain security market is inflecting.

Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization

StepSecurity now shows which GitHub Actions secrets are actually used, which workflows use them, and which can be replaced with OIDC.

SleeperGem RubyGems supply chain attack

SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

Malicious versions of git_credential_manager, Dendreo, and a fastlane plugin were published to RubyGems. They fetch a second stage from a Forgejo command and control host, skip CI to target developer machines, and install a persistent daemon. StepSecurity ran them under Harden-Runner to capture the full kill chain.

Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp

Harden-Runner secures third-party GitHub Actions runners. Bitrise macOS runners join Blacksmith, Depot, Namespace, and Warp Build with v2.20.0

Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners

Harden-Runner v2.20.0 extends egress block mode to macOS and Windows GitHub-hosted runners, so you can stop secret exfiltration on every OS your pipelines run on, not just observe it.

Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet

Device Policy lets security teams allow-list VS Code extensions and enforce it fleet-wide through Intune, Jamf, Kandji, or the DMG agent. No MDM required.

Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories

On July 14, 2026 at 07:10 UTC, three packages in the AsyncAPI generator monorepo (@asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, and @asyncapi/generator-components@0.7.1) were published to npm carrying an obfuscated dropper that fires the moment the library is loaded, not on install. The packages were published through the project's own legitimate GitHub Actions release workflow and carry valid npm OIDC provenance attestations, because the attacker didn't steal an npm token: they gained push access to the repository's next branch and let the project's real CI/CD pipeline do the publishing for them.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.