Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

GhostAction Returns: Malicious “Security Audit” Workflows Now Mine Credentials from Entire Git Histories

GhostAction returns: compromised maintainers push a fake security-audit.yml workflow that steals CI/CD secrets and cloud credentials from GitHub repos.

StepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines

Inventory the AI agent skills on developer machines and in your GitHub repositories: which agent loads them, what they can execute, and where they came from.

Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It

The malicious release was built from the project's own main branch and published with an npm provenance attestation.

SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors

On October 5, 2026, StepSecurity analyzed @subql/common@5.8.3 on npm and identified a hidden payload that collects credentials and supports remote shell access. It starts during installation and when the package is imported. The code targets developer workstations and CI environments, including GitHub Actions runners and accessible cloud services.

Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes

Compromised MemTensor npm releases turn an AI memory plugin into a credential-harvesting entry point, exposing prompts and creating a path to further package compromise.

Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners

Harden-Runner now secures GitHub Actions jobs running on AWS CodeBuild-hosted runners, on EC2 compute, with managed or custom images.

Introducing deny list egress policies for Harden-Runner

A new denied-endpoints input blocks the destinations you name and leaves everything else reachable. Here is why that matters, and how to use it to stop CI from bypassing your package proxy

openapi-react-query-codegen compromised through an exposed npm publishing workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.