2026-10-11 18:00 UTC

developer-supply-chain

band: warmmomentum: stable score: 0.471
temperature history

Episodes (3)

Optimus Labs claims coder-registry infrastructure can be hijacked with a large enough blast radius to compromise dependency distribution across coding agents and developer workflows, requiring stronger registry isolation and package-provenance controls.
expiredknownscott: low
Frank Wiles reports a targeted campaign delivered a Dropbox-shared .git folder whose malicious post-checkout hook used a Vercel app for command and control โ€” downloading an OS-specific binary, executing it, and self-deleting โ€” in an attempt to steal his developer credentials; more victims surfacing, or git platforms and security tooling explicitly countering checkout-time hook execution, would establish this as an established developer-supply-chain TTP with direct implications for agents cloning untrusted repositories.
seedknownscott: medium
StepSecurity researchers report @subql/[email protected] โ€” published through SubQuery's npm trusted-publisher (GitHub Actions OIDC) pipeline โ€” carries a postinstall credential stealer harvesting env vars, GitHub/SSH/cloud/Kubernetes/Vault secrets and AI-agent configs to ci-artifacts.dev, planting a secrets-dumping workflow branch and reverse shell; npm and maintainer remediation, victim scope, and the pipeline root-cause decide whether trusted publishing and install-time scripts remain a standing supply-chain exposure for developer and agent workflows.
watchingknownscott: low