The StepSecurity Platform

Supply chain attacks move through five stages.
So do we.

Malicious code travels from a public registry to a laptop, into a repo, through a build, and out to your users. StepSecurity puts a control at every hop. The same platform runs from the first npm install to the final release.

Public registriesnpm · PyPI · VS Code Marketplace Secure Registry
💻
Developer machineshumans + AI coding agents Dev Machine Guard
Code reposwhat gets merged Code Repo Security
CI/CD pipelinesGitHub Actions, GitLab, ADO, Jenkins… CI/CD Security
🚀
Releasewhat your users run protected upstream

Secure Registry sits at the entry point. The same cooldown and blocking policies apply whether a package is pulled by a laptop or a build runner.

Why one layer is not enough

Attackers chain layers together

In May 2026, five supply chain attacks landed within 48 hours and hit every layer of the pipeline at once. One poisoned IDE extension on a single laptop ended with roughly 3,800 internal repositories exfiltrated from one of the most security mature engineering organizations in the world. At every step, credentials stolen from one layer became the weapon against the next.

1
A dev machine fallsA poisoned IDE extension with over 2 million installs steals GitHub, npm, and cloud tokens from developer laptops.
2
Stolen tokens reach CI/CDHijacked build actions read runner process memory and harvest pipeline credentials from more than 130 file paths.
3
CI credentials fuel a wormStolen npm tokens let a self-replicating worm publish itself to new packages with no human involved.
4
The ecosystem delivers it to youTrusted SDKs and packages with millions of weekly downloads carry the payload into every org that installs them.
A registry gateway alonecannot stop a poisoned IDE extension. It never transits a registry proxy.
Package scoring alonecannot flag a trusted build action whose version tags were hijacked. It looked legitimate until the moment it was not.
A perimeter firewall alonecannot reach GitHub hosted runners. They sit outside your network entirely.
Read the full 48 hour timeline ↗
Platform at a glance

Prevent. Detect. Respond.
On every surface.

The same matrix our docs use. Every cell links to the capability behind it.

Developer Machineslaptops, agents, IDEs
Code Reposwhat gets merged
CI/CD Pipelineswhat gets built & shipped
Preventstop it before it lands
Allowlist IDE extensions and AI agents; package cooldowns block day-zero malicious releases.
Dev Machine Guard docs ↗Secure Registry docs ↗
GitHub Checks block PRs with compromised or just-published packages. Orchestrate Security hardens every repo via policy-driven PRs: pinned actions, secure configs, least-privilege tokens.
GitHub Checks docs ↗Orchestrate Security docs ↗
Egress policies block unknown outbound calls; workflow run policies gate what can execute.
Harden Runner docs ↗Workflow Run Policies docs ↗
Detectknow within minutes
Live inventory of AI agents, MCP servers, extensions and local deps, checked against threat intel.
Dev Machine Guard docs ↗
Org-wide package search + historical dependency timeline: were we ever exposed?
OSS Package Search docs ↗
eBPF baselines every network call, file write and process; anomalies alert in real time; stale and unrotated secrets flagged.
Detections docs ↗
Respondcontain and clean up
Find every machine that pulled a bad version: who, when, where.
Secure Registry
Incident pages show exact impact per repo; fixes ship org-wide from one screen.
Code Repo Security
Block C2 callbacks mid-run; detections deep-link to full runtime evidence.
CI/CD Security
Defense in depth, by design

A native enforcement point on every surface

Registry gateways only see the traffic that clients route to them. Scanners watch source code and production infrastructure. Neither watches what runs inside a CI runner or on a developer laptop. StepSecurity puts enforcement where each attack actually lands.

Dev machines
The approved path is the default pathManaged configuration routes installs through Secure Registry while your existing firewall closes the direct route to public registries. Dev Machine Guard sees what never touches a registry: IDE extensions, MCP servers, and AI agents.
CI/CD runners
Enforcement where firewalls cannot reachGitHub hosted runners sit outside your corporate network. Harden Runner enforces egress policy on the runner itself, GitHub hosted or self hosted, and attributes every download to a specific job.
The registry
One policy engine for every installSecure Registry applies cooldown periods, compromised package blocking, and typosquat protection to everything that flows through it, from laptops and from CI, in one dashboard.
Pull requests
A backstop when something slips pastA bot dependency bump or a manifest edited on an unmanaged device still gets caught. GitHub Checks run the same policies at PR time and fail the check before merge.
In an incident, one search covers every surface. CI downloads carry a job ID and laptop downloads carry a device serial number, so you know exactly who pulled what, and where.

Four products. One control plane.

CI/CD Security

Harden-Runner watches every call, write, and process at runtime. Around it: actions governance, workflow run policies, and secrets hygiene.

CI/CD
Explore CI/CD Security →
💻
Dev Machine Guard

Visibility and policy for the new dev machine: AI coding agents, MCP servers, IDE extensions, and local dependencies.

Dev Machines
Explore Dev Machine Guard →
Secure Registry

A policy gate between public registries and everything you build. One rule set, enforced on laptops and in CI.

Dev MachinesCI/CD
Explore Secure Registry →
Code Repo Security

GitHub Checks screen every PR. Orchestrate Security hardens every repo with policy-driven PRs. Package search and dependency timeline answer "were we exposed?"

Code Repos
Explore Code Repo Security →
Powered by threat intelligence

The team that found axios, Trivy, and Shai-Hulud feeds every product.

StepSecurity's threat intelligence team has detected and disclosed some of the largest supply chain attacks in the industry. Every detection they publish becomes a rule your registry gate, PR checks, and runners enforce automatically, usually before the ecosystem catches up.

See recent detections
Jul 14HIGHAsyncAPI generator: malicious next branch published to npm
Jul 13HIGHjscrambler npm package: Rust binary smuggled as JS
Jul 13HIGHInjective: 18 packages backdoored, wallet keys stolen
Jul 13MED@immobiliarelabs Backstage plugins: Miasma and phantom-gyp
Jun 25HIGHLeo Platform: 20 npm packages compromised
StepSecurity's cutting-edge security features are a core part of Mercari's supply chain security strategy. Adding these isolation, monitoring and governance capabilities to our platform has enabled Mercari's Security Engineering team to spend more time focusing on the areas that are truly unique to our enterprise.
Allan Wirth
Manager of Platform and AI Security, Mercari
From the Mercari case study →

See your own coverage map in 15 minutes