Threat Intel
Supply chain attacks, discovered first
StepSecurity's threat intelligence team is consistently among the first in the industry to discover, analyze, and report software supply chain compromises. Every advisory ships with full IOCs, affected versions, and remediation steps. And every advisory feeds automated protection into the platform within minutes.
1M+
reads of our threat research in the last 90 days
First to report
on incidents like tj-actions, axios, Trivy, and Shai-Hulud
Minutes
from confirmed compromise to automated blocking for customers
Cited by
CISA, package maintainers, and the security press
Latest alerts
Active and recent supply chain attacks
Objective evidence
Acknowledged by the maintainers and vendors we help
Our detections and disclosures are on the public record. Here is what that looks like.

First to notify maintainers and community
When we confirm a compromise, maintainers hear it from us first. For the axios and redhat-cloud-services npm compromises, we notified the maintainers and published the advisories that alerted the community.
See the axios disclosure
Covered by security press
Our incident research is regularly picked up and cited by security media and industry reporting, bringing major supply chain compromises to public attention.
Read the coverage
Publicly verifiable detections
Our detection insights for open-source projects are public. Anyone can independently confirm the axios C2 callback we flagged in the Backstage project's workflow runs.
See the live detection
Cited by CISA
CISA advisories reference our research alongside GitHub and Microsoft, including for the axios, tj-actions, and Shai-Hulud compromises.
Read the advisoryNot just research
From discovery to automated protection in minutes
Threat intel that lives in a blog post does not protect anyone. Ours is wired directly into the StepSecurity platform.
1
Discover
Two signals no one else combines: AI Package Analyst continuously analyzes newly published package versions across ecosystems, and Harden Runner provides runtime insights from inside CI runners across thousands of repositories. This is how we find compromises first, and it is a key differentiator.
AI Package Analyst + Harden Runner runtime insights
2
Investigate
An on-call threat intelligence team investigates each and every alert before it is published. Humans confirm the compromise, reproduce the attack where possible, and notify maintainers. No auto-published noise, no false alarms in your feed.
Every alert human-verified
3
Publish and Protect
The advisory ships with affected versions, malicious domains, and remediation steps, free for everyone. For customers, the IOCs flow straight into the platform: Threat Center alerts your team, Compromised Actions Policy cancels affected runs, and Harden Runner blocks exfiltration.
Automatic, org-wide, in minutes
Want these alerts in your SIEM, with automated blocking?
Threat Center pushes advisories to Slack, Splunk, and Sentinel the moment they publish, and the platform automatically blocks known-compromised actions, packages, and domains across your organization.
