1. X
  2. StepSecurity
Log inSign up
StepSecurity
208 posts
Image
user avatar
StepSecurity
@step_security
Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner
stepsecurity.io
Joined November 2021
23
Following
963
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    StepSecurity
    @step_security
    Apr 6
    🚨 Last week, North Korean state actors hijacked axios on npm. 300M+ weekly downloads. Turned into a remote access trojan. We just published the behind-the-scenes story of how we detected it, fought the threat actor in real time, and helped the community respond.
    5.4K
  • user avatar
    StepSecurity
    @step_security
    Jul 31
    🚨 Anthropic disclosed that during a cybersecurity evaluation, a Claude model published a malicious Python package to the real PyPI registry with no human operator. The package was live for about one hour and was installed on 15 real systems, including a security company's
    Image
    Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It -...
    From stepsecurity.io
    2.5K
  • user avatar
    StepSecurity
    @step_security
    Jul 28
    🚨 Two Joyfill npm packages were hijacked to ship an obfuscated remote access trojan and credential stealer. If you installed a 2773 beta, treat that machine as compromised. On July 28, 2026, malicious beta versions of @joyfill/components and @joyfill/layouts were published to
    Image
    Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access...
    From stepsecurity.io
    626
  • user avatar
    StepSecurity
    @step_security
    Jul 19
    🚨 BREAKING: SleeperGem, a RubyGems supply chain attack that skips CI to hunt developer laptops. Between July 18 and 19, malicious versions of three gems were published: git_credential_manager (impersonating Microsoft's official tool), Dendreo, and a fastlane plugin. What makes
    Image
    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent...
    From stepsecurity.io
    1.2K
  • user avatar
    StepSecurity
    @step_security
    Jul 14
    🚨 Another supply chain attack is showing why "verified provenance" isn't the same as "safe." 📦 Three packages from the AsyncAPI generator monorepo are live on npm right now carrying an obfuscated malware dropper: • @asyncapi/[email protected] •
    Image
    Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in...
    From stepsecurity.io
    2.3K
  • See @step_security's full profile

    Sign up
    Log in
Advertisement
Advertisement