Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News


stepsecurity.io > blog > 7nohe-openapi-react-query-codegen-compromised-npm-publishing-workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

2+ week, 2+ day ago   (602+ words) The attacker did not need a maintainer npm password or a long lived npm token. The repository accepted an npm publish comment from any pull request participant, checked out that pull request, installed its dependencies, and published packages with a…...


stepsecurity.io > case-studies > utility-warehouse

How Utility Warehouse Secured Its Software Supply Chain Across CI/CD, NPM, and Developer Machines with StepSecurity

2+ week, 5+ day ago   (316+ words) Utility Warehouse is the UK’s only genuine multiservice utility provider, supplying energy, broadband, mobile, and insurance to over 1.4 million customer accounts. Utility Warehouse, owned by FTSE 250-listed Telecom Plus, is one of the UK’s largest independent energy suppliers. Utility Warehouse’s…...