Build1 distinct publisher3 min readUpdated
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
The monthly figures are worth adding up. March through July account for 47 of the 50 incidents dated from February onward, which leaves February itself holding three [7]. Averaged out, the first half of the window ran at about one confirmed incident a month and the second at about eight [8]. That eightfold change is the report's real content, and it is also the part most exposed to a boring explanation: the same analysts, a customer base that presumably grew, and a monitoring product being widened into the rest of the delivery path during the period [14]. Nothing in the published method separates a busier attacker population from a wider net. The report at least tells you which one it is measuring, which is more than most vendor counts do [2].
The exclusions are the most defensible thing in the document. By dropping typosquats, name-confusion packages and anything malicious from its first release [4], Sharma is counting the takeover of trust that already existed: a maintainer account, or a mutable Action tag on a workflow a team already runs [3]. That is a narrow denominator, but it is a stable one, and the 47 incidents across the five months from March work out to one every 3.3 days, which matches the cadence the report claims [18].
Then there is the number that will get quoted. StepSecurity says the Team PCP campaign took 78,330 secrets from the pipelines of 2,186 organizations in five days in March [10], roughly 36 secrets per organization [16]. CloudSEK's underlying disclosure counts more than 2,500 organizations and about 434,000 potentially exposed pipelines, and warns that being in the set does not prove anything was stolen [12]. So the larger set carries the more cautious label, while the tighter figure sits on top of it; StepSecurity's 78,330 is best read as its analysis of observed secret records rather than 78,330 verified thefts [13]. For anyone running the affected jobs the distinction is mostly paperwork, since a cloud key or publishing credential that may have been read still has to be treated as burned [19]. The poisoned components named include the Trivy and Checkmarx KICS GitHub Actions, the telnyx Python package and LiteLLM [11].
Sharma came out of nearly 15 years at Microsoft and Azure's Green Team, his co-founder Ashish Kurmi out of security engineering at Microsoft, Uber and Plaid, and both cite SolarWinds and Codecov as the reason they went after CI/CD [15]. That history explains the quality of the case set and also its shape: the sample leans toward the registries, developer tools and pipelines its researchers already watch, and will miss what happens outside them [20].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Sharma is using the findings to expand StepSecurity from GitHub Actions monitoring into security for the full software delivery path.
StepSecurity CEO and co-founder Varun Sharma published the vendor's first annual threat report on August 22, counting 56 malicious open-source supply chain compromises over the preceding 12 months.
Every one of the 56 incidents had generated an alert for StepSecurity customers, making the total a record of what Sharma's threat intelligence operation caught rather than an independent census of open-source supply chain attacks worldwide.
The sample covers confirmed compromises of components developers already trusted: malicious releases on npm, PyPI, RubyGems, Composer and crates.io, poisoned GitHub Action tags, and compromised IDE extensions.
StepSecurity excluded conventional software vulnerabilities, unconfirmed suspicious activity, and packages malicious from their first release, including typosquats and name-confusion packages.
Sharma reported six incidents from August 2025 through January 2026, then 50 from February onward, with 13 in March, nine each in April and May, 10 in June and six in July.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's self-published telemetry, transparently bounded
All figures trace to a single publisher relaying a single vendor's own report, with no independent dataset in the cluster. What raises the score above the floor is that the methodology is stated (inclusion and exclusion rules, named ecosystems, month-by-month counts) and the article itself checks the largest number against the underlying CloudSEK disclosure, which uses a more cautious exposure framing. What holds it down is that every incident is a StepSecurity alert, the collection is admittedly biased toward the systems its researchers monitor, and the central finding - the February step change - is left unattributed.
Attack pattern demonstrably in the wild; vendor uptake unquantified
There is concrete evidence that the phenomenon is real and operating at scale in production pipelines: 56 confirmed compromises across five package registries plus Action tags and IDE extensions, four named self-propagating campaign families, and a March campaign touching thousands of organizations' CI/CD pipelines. What is absent is any measure of adoption on the defender side - no StepSecurity customer counts, deployment figures or usage data for Harden-Runner, Secure Registry, Dev Machine Guard or Threat Center - and no independent volume data to place the vendor's counts within the wider ecosystem.
Vendor framing runs ahead of verification; the coverage largely corrects it
Mildly positive. The vendor's own framing invites overreading - a record 56-count, an eightfold jump, 'one attack every three days', and an unusually precise 78,330 secrets stolen - when the count is an alert queue and the biggest number is an analysis of observed secret records rather than verified thefts, with the underlying CloudSEK disclosure warning that inclusion proves neither compromise nor theft. The gap is small rather than large because the single source in the cluster states these caveats plainly, refuses to treat the sample as a global census, and flags that the February change is unexplained; the residual overstatement sits in the vendor's numbers, not the reporting.
Threat report doubles as the vendor's expansion pitch
The commercial interest is direct and disclosed. StepSecurity authored the dataset, controls its inclusion rules, and maps each recurring weakness it identifies onto a product it sells while expanding from GitHub Actions monitoring into developer machines, registries and pipelines on the back of a 2024 seed round. Rising incident counts and a precise large-loss figure both support that pitch, and each new incident feeds detection rules the company markets. The article names this dynamic rather than concealing it, which is why the score is not higher still.
Internally coherent, externally unconfirmed
The numbers are arithmetically consistent - the monthly counts reconcile with the six-then-50 split and reproduce the stated three-day cadence - and the reporting is explicit about limits, which supports moderate confidence in what the report says. Confidence stops near the midpoint because a single publisher relays a single self-interested dataset, the most consequential figure is contested by its own underlying source, and no evidence in the cluster distinguishes a genuine attacker surge from growth in the vendor's visibility.
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
security
Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build1 distinct publisher
product
The arrayref compromise turned cargo update into the delivery channel1 distinct publisher
science
LiteLLM's 40 minutes on PyPI: 153GB of loot, 2,488 named orgs, and the victims nobody can name1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 23, 2026