Skip to content

Build1 publisherNot yet confirmed elsewhere3 min readPublished

56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet

StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Varun Sharma published StepSecurity's first annual threat report on August 22, counting 56 confirmed open-source supply chain compromises over 12 months.
  • The count deliberately omits vulnerabilities, unconfirmed activity, and packages that were malicious on first upload, including typosquats and name-confusion packages.
  • Six incidents fell between August 2025 and January 2026; 50 followed from February onward, peaking at 13 in March.
  • Self-propagating families tracked as Shai-Hulud, CanisterWorm, Miasma and ChainDrop chain maintainer account takeover into credential theft across repositories and build systems.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Anyone who needs an industry attack rate for build pipelines still does not have one, and the most credible case set available says so about itself in writing.
  • contradiction The same five-day campaign reads as a precise theft total in one report and an unproven exposure set in the other, which changes whether a security team is running an incident or an inventory.
  • decision If takeover of existing trust is the entry route, detection tuned to suspicious new package names buys little; the trigger has to be familiar packages and pinned Action tags changing underneath you.
  • precedent A vendor's alert corpus is now the reference number for CI attacks, so expect competing counts with looser definitions and larger totals to follow.

The monthly figures are worth adding up. March through July account for 47 of the 50 incidents dated from February onward, which leaves February itself holding three [15]. Averaged out, the first half of the window ran at about one confirmed incident a month and the second at about eight [16]. That eightfold change is the report's real content, and it is also the part most exposed to a boring explanation: the same analysts, a customer base that presumably grew, and a monitoring product being widened into the rest of the delivery path during the period [1]. Nothing in the published method separates a busier attacker population from a wider net. The report at least tells you which one it is measuring, which is more than most vendor counts do [3].

The exclusions are the most defensible thing in the document. By dropping typosquats, name-confusion packages and anything malicious from its first release [5], Sharma is counting the takeover of trust that already existed: a maintainer account, or a mutable Action tag on a workflow a team already runs [4]. That is a narrow denominator, but it is a stable one, and the 47 incidents across the five months from March work out to one every 3.3 days, which matches the cadence the report claims [18].

Then there is the number that will get quoted. StepSecurity says the Team PCP campaign took 78,330 secrets from the pipelines of 2,186 organizations in five days in March [19], roughly 36 secrets per organization [17]. CloudSEK's underlying disclosure counts more than 2,500 organizations and about 434,000 potentially exposed pipelines, and warns that being in the set does not prove anything was stolen [10]. So the larger set carries the more cautious label, while the tighter figure sits on top of it; StepSecurity's 78,330 is best read as its analysis of observed secret records rather than 78,330 verified thefts [11]. For anyone running the affected jobs the distinction is mostly paperwork, since a cloud key or publishing credential that may have been read still has to be treated as burned [13]. The poisoned components named include the Trivy and Checkmarx KICS GitHub Actions, the telnyx Python package and LiteLLM [9].

Sharma came out of nearly 15 years at Microsoft and Azure's Green Team, his co-founder Ashish Kurmi out of security engineering at Microsoft, Uber and Plaid, and both cite SolarWinds and Codecov as the reason they went after CI/CD [12]. That history explains the quality of the case set and also its shape: the sample leans toward the registries, developer tools and pipelines its researchers already watch, and will miss what happens outside them [14].

What to watch

  • Whether the months after July hold in the six-to-ten band or fall away, which is the cheapest available test of whether February was an attacker event or a coverage event.
  • Whether CloudSEK or any named organization confirms how many of the recorded secret records were valid credentials that were actually used.
  • Whether a second vendor publishes a case set using the same exclusions, which would finally give the 56 something to be compared against.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence46
Adoption42
Hype gap+16
Incentives79
Confidence51
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Sharma is using the findings to expand StepSecurity from GitHub Actions monitoring into security for the full software delivery path.

  2. [2]

    StepSecurity CEO and co-founder Varun Sharma published the vendor's first annual threat report on August 22, counting 56 malicious open-source supply chain compromises over the preceding 12 months.

    ReportedSupportedSource: StepSecurity annual threat report, via runtimewire.comView cited source
  3. [3]

    Every one of the 56 incidents had generated an alert for StepSecurity customers, making the total a record of what Sharma's threat intelligence operation caught rather than an independent census of open-source supply chain attacks worldwide.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. runtimewire.com

    1 article · August 23, 2026

    StepSecurity counted 56 supply chain attacks, all from its own alerts

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories