StepSecurity has detected a new npm supply chain attack campaign using preinstall hooks to download the Bun JavaScript runtime and execute an 11 MB obfuscated payload. At least two SAP-ecosystem ...
On March 16, 2026, StepSecurity Threat Intel was the first to detect and report malicious releases in two popular React Native npm packages — react-native-international-phone-number and ...
What is supported Harden-Runner supports GitHub Actions runners hosted on AWS CodeBuild on EC2 compute, starting with the Harden-Runner GitHub Action v2.20.1. v2.21.0 extends that to CodeBuild runners ...
Ports are not part of a deny list entry. A denied endpoint is denied on every port, and if you write one anyway it is stripped and ignored. registry.example.com:443 denies registry.example.com on ...
Building on our solid foundation, we're thrilled to enter the next phase of growth to empower the open-source community and enterprises to secure their CI/CD pipelines ...
This case study is written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx, based on Checkmarx's experience using StepSecurity at scale. The rollout was led by Yevgeny ...
Have a question or feedback? We would love to hear from you. Submit the form below or email us directly at info@stepsecurity.io ...
A malicious version of elementary-data (0.23.3) was published to PyPI and is, at the time of writing, still listed as the latest release. The same release run also pushed a multi-arch container image ...
@bitwarden/cli@2026.4.0 — the official command-line interface for the Bitwarden password manager — was found compromised on npm. A malicious preinstall hook silently bootstraps the Bun JavaScript ...
Version 18.95.0 of the popular Nx Console extension (2.2M+ installs) was published with malicious code targeting developer credentials, cloud infrastructure tokens, and CI/CD secrets.
Active Supply Chain Attack: Malicious node-ipc Versions Published to npm StepSecurity has detected multiple malicious releases of the popular node-ipc npm package. Three versions are currently known ...
CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results