Build1 publisherNot yet confirmed elsewhere3 min readPublished
56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
The Engineer · Build desk
What happened
- Varun Sharma published StepSecurity's first annual threat report on August 22, counting 56 confirmed open-source supply chain compromises over 12 months.
- The count deliberately omits vulnerabilities, unconfirmed activity, and packages that were malicious on first upload, including typosquats and name-confusion packages.
- Six incidents fell between August 2025 and January 2026; 50 followed from February onward, peaking at 13 in March.
- Self-propagating families tracked as Shai-Hulud, CanisterWorm, Miasma and ChainDrop chain maintainer account takeover into credential theft across repositories and build systems.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Anyone who needs an industry attack rate for build pipelines still does not have one, and the most credible case set available says so about itself in writing.
- contradiction The same five-day campaign reads as a precise theft total in one report and an unproven exposure set in the other, which changes whether a security team is running an incident or an inventory.
- decision If takeover of existing trust is the entry route, detection tuned to suspicious new package names buys little; the trigger has to be familiar packages and pinned Action tags changing underneath you.
- precedent A vendor's alert corpus is now the reference number for CI attacks, so expect competing counts with looser definitions and larger totals to follow.
The monthly figures are worth adding up. March through July account for 47 of the 50 incidents dated from February onward, which leaves February itself holding three [15]. Averaged out, the first half of the window ran at about one confirmed incident a month and the second at about eight [16]. That eightfold change is the report's real content, and it is also the part most exposed to a boring explanation: the same analysts, a customer base that presumably grew, and a monitoring product being widened into the rest of the delivery path during the period [1]. Nothing in the published method separates a busier attacker population from a wider net. The report at least tells you which one it is measuring, which is more than most vendor counts do [3].
The exclusions are the most defensible thing in the document. By dropping typosquats, name-confusion packages and anything malicious from its first release [5], Sharma is counting the takeover of trust that already existed: a maintainer account, or a mutable Action tag on a workflow a team already runs [4]. That is a narrow denominator, but it is a stable one, and the 47 incidents across the five months from March work out to one every 3.3 days, which matches the cadence the report claims [18].
Then there is the number that will get quoted. StepSecurity says the Team PCP campaign took 78,330 secrets from the pipelines of 2,186 organizations in five days in March [19], roughly 36 secrets per organization [17]. CloudSEK's underlying disclosure counts more than 2,500 organizations and about 434,000 potentially exposed pipelines, and warns that being in the set does not prove anything was stolen [10]. So the larger set carries the more cautious label, while the tighter figure sits on top of it; StepSecurity's 78,330 is best read as its analysis of observed secret records rather than 78,330 verified thefts [11]. For anyone running the affected jobs the distinction is mostly paperwork, since a cloud key or publishing credential that may have been read still has to be treated as burned [13]. The poisoned components named include the Trivy and Checkmarx KICS GitHub Actions, the telnyx Python package and LiteLLM [9].
Sharma came out of nearly 15 years at Microsoft and Azure's Green Team, his co-founder Ashish Kurmi out of security engineering at Microsoft, Uber and Plaid, and both cite SolarWinds and Codecov as the reason they went after CI/CD [12]. That history explains the quality of the case set and also its shape: the sample leans toward the registries, developer tools and pipelines its researchers already watch, and will miss what happens outside them [14].
What to watch
- Whether the months after July hold in the six-to-ten band or fall away, which is the cheapest available test of whether February was an attacker event or a coverage event.
- Whether CloudSEK or any named organization confirms how many of the recorded secret records were valid credentials that were actually used.
- Whether a second vendor publishes a case set using the same exclusions, which would finally give the 56 something to be compared against.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Sharma is using the findings to expand StepSecurity from GitHub Actions monitoring into security for the full software delivery path.
- [2]
StepSecurity CEO and co-founder Varun Sharma published the vendor's first annual threat report on August 22, counting 56 malicious open-source supply chain compromises over the preceding 12 months.
- [3]
Every one of the 56 incidents had generated an alert for StepSecurity customers, making the total a record of what Sharma's threat intelligence operation caught rather than an independent census of open-source supply chain attacks worldwide.
- [4]
The sample covers confirmed compromises of components developers already trusted: malicious releases on npm, PyPI, RubyGems, Composer and crates.io, poisoned GitHub Action tags, and compromised IDE extensions.
- [5]
StepSecurity excluded conventional software vulnerabilities, unconfirmed suspicious activity, and packages malicious from their first release, including typosquats and name-confusion packages.
- [6]
Sharma reported six incidents from August 2025 through January 2026, then 50 from February onward, with 13 in March, nine each in April and May, 10 in June and six in July.
- [7]
StepSecurity describes the pace since March as roughly one confirmed attack every three days.
- [8]
The report's largest change is self-propagating campaigns: a compromised maintainer account exposes every package that maintainer controls, and stolen credentials then reach further packages, repositories and build systems, a pattern traced through Shai-Hulud, CanisterWorm, Miasma and ChainDrop.
- [9]
Sharma's report says the Team PCP attackers poisoned trusted components including the Trivy and Checkmarx KICS GitHub Actions, the telnyx Python package and LiteLLM.
- [10]
The underlying CloudSEK disclosure describes a reconstructed exposure set of more than 2,500 organizations and roughly 434,000 potentially exposed CI/CD pipelines, and explicitly warns that inclusion does not prove every organization was compromised or every listed credential stolen.
- [11]
StepSecurity's exact 78,330 figure should be read as its analysis of observed secret records rather than proof of 78,330 independently verified thefts.
- [12]
Sharma spent nearly 15 years at Microsoft and led Azure's Green Team; co-founder Ashish Kurmi previously held security engineering roles at Microsoft, Uber and Plaid; the founders say SolarWinds and Codecov pushed them to build protections for CI/CD pipelines.
- [13]
The verification distinction does not remove the operational risk: a potentially exposed cloud key, repository token or package-publishing credential still has to be dealt with.
- [14]
The sample will miss attacks outside StepSecurity's visibility and leans toward the registries, developer tools and CI/CD systems its researchers monitor, but remains useful for tracing change within a fixed security operation over time.
- [15]
March through July account for 47 of the 50 incidents dated from February onward, leaving three for February.
- [16]
The six months from August 2025 through January 2026 average one confirmed incident a month; the six months from February average about 8.3, roughly eight times the earlier rate.
- [17]
StepSecurity's Team PCP figures work out to about 36 secrets per affected organization.
- [18]
The 47 incidents dated March through July average one confirmed attack every 3.3 days, consistent with the report's stated cadence of one every three days.
- [19]
StepSecurity's report says the Team PCP campaign stole 78,330 secrets from the CI/CD pipelines of 2,186 organizations during five days in March.
ReportedContestedSource: StepSecurity report2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- runtimewire.comStepSecurity counted 56 supply chain attacks, all from its own alerts
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Software Supply Chain SecurityFollow
- Package Registry EcosystemsFollow
- Vendor Threat Intelligence MethodologyFollow
- CI/CD Pipeline SecurityFollow
- Secrets Exposure and RotationFollow
- Self-Propagating Malware CampaignsFollow
Entities
- StepSecurityFollow
- Varun SharmaFollow
- Ashish KurmiFollow
- CloudSEKFollow
- Team PCPFollow
- Shai-HuludFollow
- CanisterWormFollow
- MiasmaFollow
- ChainDropFollow
- GitHub ActionsFollow
- Harden-RunnerFollow
- Secure RegistryFollow
- Dev Machine GuardFollow
- Threat CenterFollow
- npm registryFollow
- PyPIFollow
- RubyGemsFollow
- ComposerFollow
- crates.ioFollow
- TrivyFollow
- Checkmarx KICSFollow
- LiteLLMFollow
- telnyx (Python package)Follow
- Runtime VenturesFollow
- MicrosoftFollow