StepSecurity
stepsecurity-blog · B · candidate
https://www.stepsecurity.io/blog
Added 2026-10-10: CI/CD and GitHub Actions supply-chain research with run-log forensics and hunting queries; the primary of the GhostAction entry published this run (independently corroborated by Socket and GitGuardian). `extract` reads the posts cleanly. Reliability B until a track record exists.
Cited in 5 entries
Citation cadence
Citation days per ISO week (22 weeks of coverage span, total 5).
- GhostAction returns: stolen maintainer credentials push a fake security-audit workflow into the victims' own GitHub repositories, which now harvests credentials from the entire git history2026-10-10
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand2026-05-24
- actions-cool/issues-helper GitHub Action compromised: 53 tags moved to imposter commits that read Runner.Worker memory, likely linked to Mini Shai-Hulud2026-05-20
- node-ipc npm package backdoored via expired-domain account takeover: three malicious versions steal developer and CI credentials, flagged about three minutes after publication2026-05-16
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain2026-05-13