Overlooked Attack Surfaces
Unaddressed Software Supply Chain Security Risks Leave Companies Open to Compromise
March 2026
axios Compromised on npm
Supply Chain Attack
Hijacked maintainer account used to publish poisoned axios releases injecting a hidden dependency that drops a cross-platform remote access trojan on install. attack
March 2026
Trivy Compromised
Malicious trivy-action exfiltrated CI/CD secrets to an attacker-controlled domain for 12 hours. A fake trivy binary release was also published to GitHub Releases.
March 2025
tj-actions/changed-files action is compromised
Application Security
Learn how StepSecurity Harden-Runner detected the tj-actions/changed-files supply chain attack
From Our Threat Intelligence Team
The attacks making headlines? Our team keeps finding them first.
Every advisory ships free with affected versions, IOCs, and remediation steps. Customers get automated blocking within minutes.
The Platform
Independent defenses at every control point in software delivery.
No other platform defends every control point. Click any capability to explore it.
CI/CD Security
→
Behavioral analysis blocks compromised packages inside your build runners.
Dev Machine Guard
→
Control and governance for AI coding agents, IDE extensions, and open source packages.
Secure Registry
→
Automatically blocks compromised packages across your entire pipeline.
Code Repo Security
→
Every PR screened. Remediation pull requests opened automatically across your repos.
Threat Intel
→
First to detect tj-actions, axios, Trivy, Shai-Hulud, and other major attacks.
Maintained Actions
→
Secure, drop-in replacements for risky third-party GitHub Actions.
One Platform. Every Layer.
Attackers hit every layer of your pipeline. So do our defenses.
Independent security controls at every stage of software delivery, so an attacker who slips past one layer is caught at the next. Here is how that plays out against the supply chain attacks that actually happened.
Dev Machines
Dev Machine
Guard
Guard
Code Repos
GitHub
Checks
Checks
CI/CD
Harden
Runner
Runner
CI/CD
GitHub
Actions
Actions
Everywhere
Threat
Center
Center
Everywhere
Secure
Registry
Registry
Miasma Worm Targets AI Coding Agents
AI coding agents · Jun 2026
✓
✓
✓
✓
✓
Megalodon: Mass CI/CD Secret Exfiltration
CI/CD · May 2026
✓
✓
✓
✓
Nx Console VS Code Extension Compromised
Dev machine · May 2026
✓
✓
Shai-Hulud npm Worm Campaigns
OSS Dependencies · 2025-26
✓
✓
✓
✓
✓
axios Compromised on npm
OSS Dependencies · Mar 2026
✓
✓
✓
✓
✓
Trivy Compromised
CI/CD + Dev machine · Mar 2026
✓
✓
✓
✓
✓
Why Step Security
Why enterprises pick StepSecurity
We defend every control point.
Developer machines, registries, code repos, and CI/CD.
We deploy in an afternoon.
One line of YAML for CI, one config line for the registry, one MDM push for laptops. Nothing to host.
We find the attacks first.
tj-actions, axios, Trivy, and Shai-Hulud were all detected here first.
Why Step Security
Experience the StepSecurity Difference
