StepSecurity has detected a new npm supply chain attack campaign using preinstall hooks to download the Bun JavaScript runtime and execute an 11 MB obfuscated payload. At least two SAP-ecosystem ...
On March 16, 2026, StepSecurity Threat Intel was the first to detect and report malicious releases in two popular React Native npm packages — react-native-international-phone-number and ...
What is supported Harden-Runner supports GitHub Actions runners hosted on AWS CodeBuild on EC2 compute, starting with the Harden-Runner GitHub Action v2.20.1. v2.21.0 extends that to CodeBuild runners ...
Ports are not part of a deny list entry. A denied endpoint is denied on every port, and if you write one anyway it is stripped and ignored. registry.example.com:443 denies registry.example.com on ...
Building on our solid foundation, we're thrilled to enter the next phase of growth to empower the open-source community and enterprises to secure their CI/CD pipelines ...
This case study is written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx, based on Checkmarx's experience using StepSecurity at scale. The rollout was led by Yevgeny ...
Have a question or feedback? We would love to hear from you. Submit the form below or email us directly at info@stepsecurity.io ...
On June 8, 2026, multiple Graph ML PyPI packages in the bioinformatics ecosystem were compromised in the Hades campaign, deploying cross-platform memory scrapers, AI prompt injections to misdirect ...
self-replicating worm is spreading across the npm registry using binding.gyp, a file that triggers code execution during npm install without touching package.json scripts. The attack bypasses ...
A coordinated 8-month supply chain attack planted credential-stealing code inside fake AI coding assistants on the JetBrains Marketplace, quietly exfiltrating OpenAI, DeepSeek, and SiliconFlow API ...
A malicious version of elementary-data (0.23.3) was published to PyPI and is, at the time of writing, still listed as the latest release. The same release run also pushed a multi-arch container image ...
@bitwarden/cli@2026.4.0 — the official command-line interface for the Bitwarden password manager — was found compromised on npm. A malicious preinstall hook silently bootstraps the Bun JavaScript ...