logo

SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines

ID: 6e24fefd-664c-5bc0-8731-87a549b311b8

STIX ID: report--6e24fefd-664c-5bc0-8731-87a549b311b8

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-04-28

Author: Mirko Zorz

...
...

SmokedMeat is an open-source framework from Boost Security that executes end-to-end attack chains against CI/CD infrastructure to demonstrate the real impact of pipeline vulnerabilities — from deploying payloads and compromising runners to harvesting credentials and pivoting to cloud resources. The report cites the March 2026 TeamPCP supply-chain campaign, which compromised Trivy, Checkmarx, LiteLLM, and many npm packages, as evidence of how pipeline injection and unpatched findings can lead to large-scale cascade attacks; SmokedMeat is offered to help teams visualize and prioritize remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.