StepSecurity
Related tags:
Posts about cyberPosts about cicdPosts about malwarePosts about npmPosts about github-actionsPosts about security
Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat Execute a Remote Payload at Build TimeTeam PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.Control Which Package Registries Your CI Jobs and Developer Machines UseChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran ItDev Machine Guard Now Inventories AI Agent Skills on Developer MachinesCompromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access TrojanCompromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials2026 Mid-Year Update: On Pace for Our Biggest Year YetFind Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization