Executive Summary
Utility Warehouse is the UK’s only genuine multiservice utility provider, supplying energy, broadband, mobile, and insurance to over 1.4 million customer accounts. Utility Warehouse, owned by FTSE 250-listed Telecom Plus, is one of the UK’s largest independent energy suppliers.
As software supply chain attacks targeting the NPM ecosystem accelerated throughout 2025, Utility Warehouse’s security team recognized an opportunity to strengthen its posture before an incident occurred. While the team had existing security capabilities, they lacked runtime visibility into CI/CD pipeline behavior, NPM dependency risk, and developer toolchains. When Utility Warehouse evaluated StepSecurity, the platform delivered immediate coverage across all three attack surfaces - and within weeks, it prevented a compromised NPM package from reaching Utility Warehouse’s codebase.
The Challenge
Utility Warehouse’s security team, led by Ryan Richardson (SOC Lead) and Christo Goosen (DevSecOps Lead), identified three areas where the organization needed stronger visibility and control.
Limited Visibility into CI/CD Dependencies
The team had no easy, centralised, way to see which GitHub Actions or NPM dependencies were in use across their pipelines, and limited mechanisms to restrict or control them. Beyond not easily knowing which dependencies were in use, they had no baseline of expected pipeline behavior, meaning they couldn't distinguish normal outbound network activity from anomalous calls that might indicate a compromise. When NPM package compromises began to increase in frequency, Utility Warehouse had been fortunate that compromised packages were typically published outside their employees' working hours, meaning they weren't pulled into builds. But the team recognized this was a matter of timing, not protection, and took a proactive approach to close the gap.
Reactive Incident Response
Several incidents involving GitHub Actions and CI/CD compromises came to the team's attention through threat intelligence channels. The team was able to respond effectively in each case, but the process relied on manual monitoring and timely awareness of external threat reports. As the frequency and sophistication of supply chain attacks continued to increase, the team wanted to move from reactive response to proactive, automated prevention, rather than depending on being in the right place at the right time.
Developer Toolchain Visibility
Developers across the organization had begun adopting AI-powered coding tools, including Claude Code, Cursor, and GitHub Copilot - with the security team having limited visibility into these toolchains. The team was also aware of the emerging risks around AI-assisted development potentially introducing vulnerable dependencies into projects.
The team was looking for a platform that could address all three concerns without adding friction to developer workflows.
Why StepSecurity
Utility Warehouse first became aware of StepSecurity through its original research and blog coverage of the NPM supply chain compromises that escalated throughout 2025 - including StepSecurity’s early detection and reporting of the Shai-Hulud campaign, which CISA subsequently cited in its own advisory.
When the team evaluated the platform, they found it addressed their specific gaps without overreaching.
“It just works. We had no issues testing it, it worked as expected and covered the gaps we were most concerned about without the product trying to cover too many bases.”
- Christo Goosen, DevSecOps Lead, Utility Warehouse
The capability that stood out most was StepSecurity’s baseline anomaly detection. Before deployment, Utility Warehouse had limited visibility into what outbound network calls their applications were making during CI/CD runs. With StepSecurity in place, the team could see all outbound calls, quickly trace them back to the exact workflow, job and step making the call, and automatically block any anomalous behavior.
“We didn’t know what was being called from within our applications, and this has changed that significantly. We can now see all outbound calls, and if something was to suddenly change like in the case of the Shai-Hulud campaign, the deployment would be stopped automatically.
- Christo Goosen, DevSecOps Lead, Utility Warehouse
Results and Impact
Since deploying StepSecurity, Utility Warehouse has gained comprehensive visibility across its software supply chain without disrupting development workflows.
Prevented a Compromised Package from Reaching Production
In Utility Warehouse’s first major prevented incident, a developer used Claude Code to refactor a project. A downstream NPM package introduced by a new dependency turned out to be compromised. StepSecurity detected and blocked the PR. The security team was able to work with the developer directly, close the pull request, and ensure the compromised package never entered the codebase beyond a draft PR.
Visibility into Developer Toolchains
Dev Machine Guard provided Utility Warehouse's security team with insights into the AI-powered developer tools being used across the organization, including which tools were in use and how they were interacting with codebases. This addressed what had previously been a visibility gap, giving the team a clearer picture of the developer toolchain landscape without requiring developers to self-report or change their workflows, and was invaluable with the increase in supply chain attacks.
Security Without Workflow Disruption
The rollout had no significant impact on developer workflows and most of their developers have not even been impacted by StepSecurity’s implementation.
“It hasn’t significantly changed our workflow, and I think that’s a very cool outcome of this rollout. Besides waiting for the checks to finish, they don’t even notice it is there, which is a win for us, as we don’t want security to be significantly impactful on teams and their processes.”
- Ryan, SOC Lead, Utility Warehouse
The Bigger Picture
The Shai-Hulud campaign, a self-replicating worm that compromised hundreds of NPM packages in September 2025 and returned in an escalated form in November, demonstrated that software supply chain attacks are no longer theoretical. CISA issued a formal advisory, and major vendors raced to respond. For Utility Warehouse, StepSecurity provided protection at multiple layers: compromised packages could be flagged and blocked at the pull request stage before entering the codebase, while baseline anomaly detection would catch any anomalous outbound network behavior during CI/CD runs and stop the deployment automatically.
Utility Warehouse’s proactive approach, deploying supply chain security before a major incident, rather than after, positioned the team to contain real-world threats with minimal disruption and maximum confidence.
“Peace of mind. With the increase in supply chain attacks, StepSecurity gives us peace of mind that this behaviour will be caught and stopped.”
- Ryan, SOC Lead, Utility Warehouse




