1. X
  2. StepSecurity
Log inSign up
StepSecurity
209 posts
StepSecurity profile banner
user avatar

StepSecurity

@step_security
Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner
stepsecurity.io
Joined November 2021
23
Following
1,000
Followers
RepliesRepliesMediaMedia
  • Pinned
    user avatar
    StepSecurity
    @step_security
    Apr 6
    🚨 Last week, North Korean state actors hijacked axios on npm. 300M+ weekly downloads. Turned into a remote access trojan. We just published the behind-the-scenes story of how we detected it, fought the threat actor in real time, and helped the community respond.
  • user avatar
    StepSecurity
    @step_security
    Aug 4
    🚨🚨 BREAKING: Popular npm packages with over 350 MILLION weekly downloads are compromised by the ChainDrop npm worm, which is spreading rapidly across the ecosystem. Our OSS Security Feed has flagged 430 malicious package releases in just the last couple of hours. Compromised
    Image
    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 - StepSecurity
    From stepsecurity.io
  • user avatar
    StepSecurity
    @step_security
    Jul 31
    🚨 Anthropic disclosed that during a cybersecurity evaluation, a Claude model published a malicious Python package to the real PyPI registry with no human operator. The package was live for about one hour and was installed on 15 real systems, including a security company's
    Image
    Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It -...
    From stepsecurity.io
  • user avatar
    StepSecurity
    @step_security
    Jul 28
    🚨 Two Joyfill npm packages were hijacked to ship an obfuscated remote access trojan and credential stealer. If you installed a 2773 beta, treat that machine as compromised. On July 28, 2026, malicious beta versions of @joyfill/components and @joyfill/layouts were published to
    Image
    Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access...
    From stepsecurity.io
  • user avatar
    StepSecurity
    @step_security
    Jul 19
    🚨 BREAKING: SleeperGem, a RubyGems supply chain attack that skips CI to hunt developer laptops. Between July 18 and 19, malicious versions of three gems were published: git_credential_manager (impersonating Microsoft's official tool), Dendreo, and a fastlane plugin. What makes
    Image
    SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent...
    From stepsecurity.io

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement