Securing the Software Supply Chain
Developer Machines
Where your developers and agents work
Code Repos
Where every code change lands
CI/CD Pipelines
Where your software gets built
Prevent, detect, and respond to supply chain attacks across every stage of software delivery. From the first line of code your team writes to the final build you ship, StepSecurity provides end-to-end defense.
Powered by a dedicated threat intelligence team that has detected and disclosed some of the largest supply chain attacks in the industry.
Overlooked Attack Surfaces
Unaddressed Software Supply Chain Security Risks Leave Companies Open to Compromise
March 2026
axios Compromised on npm
Supply Chain Attack
Hijacked maintainer account used to publish poisoned axios releases injecting a hidden dependency that drops a cross-platform remote access trojan on install. attack
March 2026
Trivy Compromised
Malicious trivy-action exfiltrated CI/CD secrets to an attacker-controlled domain for 12 hours. A fake trivy binary release was also published to GitHub Releases.
March 2025
tj-actions/changed-files action is compromised
Application Security
Learn how StepSecurity Harden-Runner detected the tj-actions/changed-files supply chain attack
One Platform. Every Layer.
Attackers hit every layer of your pipeline. So do our defenses.
Independent security controls at every stage of software delivery, so an attacker who slips past one layer is caught at the next. Here is how that plays out against the supply chain attacks that actually happened.
Dev Machines
Dev Machine
Guard
Guard
Code Repos
GitHub
Checks
Checks
CI/CD
Harden
Runner
Runner
CI/CD
GitHub
Actions
Actions
Everywhere
Threat
Center
Center
Everywhere
Secure
Registry
Registry
Miasma Worm Targets AI Coding Agents
AI coding agents · Jun 2026
✓
✓
✓
✓
✓
Megalodon: Mass CI/CD Secret Exfiltration
CI/CD · May 2026
✓
✓
✓
✓
Nx Console VS Code Extension Compromised
Dev machine · May 2026
✓
✓
Shai-Hulud npm Worm Campaigns
OSS Dependencies · 2025-26
✓
✓
✓
✓
✓
axios Compromised on npm
OSS Dependencies · Mar 2026
✓
✓
✓
✓
✓
Trivy Compromised
CI/CD + Dev machine · Mar 2026
✓
✓
✓
✓
✓
Why Step Security
Experience the StepSecurity Difference
