Skip to content

company

StepSecurity

StepSecurity is a supply chain security firm specializing in CI/CD pipeline protection, including GitHub Actions and build-time threat detection.

Known aliases

  • stepsecurity
  • Step Security
  • stepsecurity.io

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Fake Polymarket copy-trading bots hid key stealers in their npm dependencies

One attacker pushed more than twenty malicious GitHub repos from a hijacked account in February, several posing as Polymarket copy-trading bots. Garnet's maintainer published a fifteen-minute checklist for tracing what a bot does with the one signing key it needs.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+20
Incentives70
Confidence40
security6 publishers

A backdoor that fires at cargo build: the arrayref poisoning puts your build boxes in scope

Malicious versions of three Rust crates ran code at compile time on August 20. Wiz says the infrastructure overlaps with DPRK operations, so the campaign should be treated as live.

Perspective Coverage

6 publishers
Builder
Builder 45%
Operator
Operator 48%
Investor
Investor 7%

Reality

Evidence80
Adoption30
Hype gap+25
Incentives55
Confidence75
build6 publishers

cargo build stopped being a safe verb: arrayref 0.3.10 ran a payload at compile time

The Rust Security Response Team deleted proc-macro1 and arrayref 0.3.10 on August 20 after a build script fetched and launched a binary. The lure was a yank warning.

Publishers:blog.rust-lang.orgdev.tolwn.netresearch.jfrog.comruntimewire.comrustsec.orgsocket.dev

Perspective Coverage

7 publishers
Builder
Builder 38%
Operator
Operator 54%
Investor
Investor 8%

Reality

Evidence86
Adoption15
Hype gap+35
Incentives60
Confidence82
security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62
security7 publishers

Attacker copied 170 CrowdSec repositories with a departed employee's still-live GitHub token

CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.

Publishers:crowdsec.netgithub.cominfosecurity-magazine.comold.tanstack.comorca.securitysecurityweek.comthehackernews.com

Perspective Coverage

7 publishers
Builder
Builder 39%
Operator
Operator 52%
Investor
Investor 9%

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives65
Confidence60