Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
How Contrast Security Extended Runtime Security to CI/CD Runners and Developer Machines with StepSecurity
1+ day, 2+ hour ago (598+ words) Contrast Security is the leader in Application Detection and Response. Our technology protects the software of some of the biggest corporations and government entities in the world. No other product can do what we do, which is to block attacks…...
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
1+ week, 2+ day ago (1272+ words) If you installed any of the affected versions listed below, assume your system is compromised. This is a developing incident. All package and version counts in this post are as of our last update, and the number of compromised packages…...
Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It
1+ week, 5+ day ago (1011+ words) No human attacker was involved at any step. This post walks through what happened, answers a question several people have asked us directly, and lays out what this incident should change about how teams consume open source packages. Anthropic runs…...
Dev Machine Guard Now Inventories AI Agent Skills on Developer Machines
2+ week, 1+ day ago (916+ words) Dev Machine Guard now inventories AI agent skills installed on developer machines. A new Agent Skills page in the StepSecurity dashboard shows every skill detected across your fleet, which AI coding agents can load it, where it came from, and…...
Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories
2+ week, 1+ day ago (479+ words) Branch protection rules are the primary gate preventing unauthorized workflow injection. Repositories without mandatory pull request reviews allow any account with write access, or any accepted PR from a public fork with weak merge controls, to land workflow changes directly…...
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
2+ week, 1+ day ago (920+ words) StepSecurity confirmed the compromise three ways. The StepSecurity OSS AI scan feed flagged @joyfill/[email protected] as CRITICAL with a security score of 0 and a REJECTED verdict. We detonated all affected versions under Harden-Runner in a sandbox. We diffed the malicious…...
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
3+ week, 4+ day ago (755+ words) The releases were published straight to the registry with no matching commit or tag in the source projects. Two of the gems had been dormant for years before suddenly shipping new versions. StepSecurity ran every compromised version inside Harden-Runner in…...
Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners
4+ week, 16+ hour ago (338+ words) Until now, Harden-Runner could answer "no" on Linux GitHub-hosted runners with egress-policy: block. On macOS and Windows GitHub-hosted runners, teams had audit mode: full visibility into outbound traffic, but no enforcement. With Harden-Runner v2.20.0, block mode is now supported on macOS…...
Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet
4+ week, 18+ hour ago (555+ words) The pattern is consistent: extensions run with the developer's privileges, and anyone on the team can install anything the marketplace offers. Most security teams have no control over that decision. Last year, Dev Machine Guard gave you visibility into every…...
Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp
4+ week, 17+ hour ago (410+ words) Supply chain attacks do not check your runs-on label. When the Sha1-Hulud worm compromised prominent npm packages, the malicious code executed wherever npm install ran. When the Velora DEX SDK compromise dropped a macOS backdoor through npm, it did not…...