Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

openapi-react-query-codegen compromised through an exposed npm publishing workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.

Dev Machine Guard Now Inventories Browser Extensions on Developer Machines

Dev Machine Guard now inventories browser extensions across your developer fleet. See every extension installed in Chrome, Edge, and Firefox, what each one is currently permitted to do, whether it came from a marketplace or was installed some other way, and which devices are running it.

Dev Machine Guard Now Inventories Where Developer Credentials Live

Dev Machine Guard now inventories where developer tools keep credentials. See which credential sources are in use across your fleet, how many devices each one affects, and how much of that material is sitting in plaintext. Credential values, fragments, hashes, and fingerprints are never stored, displayed, or sent off the device.

The State of Open Source Supply Chain Attacks

56 supply chain attacks in 12 months, each with a StepSecurity Threat Center alert. The data, the worms, the Team PCP numbers, and how to defend.

Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

A compromised maintainer account and a same-day impersonator of one of Rust's best-known authors turned a routine cargo update into silent remote code execution. Three crates from the same owner were poisoned in 23 minutes (arrayref, internment, and append-only-vec), alongside six attacker-owned crates now deleted from crates.io. The malicious releases are gone, but the 07:11–09:25 UTC exposure window leaves an open question: who built during it? Verified timeline, IOCs, runtime detection, and remediation inside.

Team PCP CI/CD secrets heist: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations in five days, per the CloudSEK disclosure

Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's research team has tracked this threat actor across the Trivy, telnyx, and LiteLLM compromises. Here is how the campaign works, why CI/CD pipelines are the target, and the layered controls that stop it.

Control Which Package Registries Your CI Jobs and Developer Machines Use

Two StepSecurity controls show every CI job and developer machine that still installs from public registries. Once you can see them, you can block public registries in CI and centrally set the registry configuration on every developer machine.

ChainDrop npm worm blast radius: 444 packages poisoned, 2,212 malicious versions, 450M+ weekly downloads hit, 14+ orgs compromised, starting with keyv@6.0.0

ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

A self-propagating npm worm we call ChainDrop poisoned 444 packages and 2,212 versions in under four hours, starting with keyv@6.0.0. Full payload analysis, the affected package list, IOCs, and what to do now.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.