logo

The Scanner Was the Weapon: 36 Months of Precision Supply Chain Attacks Against DevSecOps Infrastructure

ID: 1ec01b55-f6ac-53ea-8b42-59e762564973

STIX ID: report--1ec01b55-f6ac-53ea-8b42-59e762564973

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-05-12

...
...

**Executive summary:** This report examines four confirmed supply‑chain compromises from March 2024–March 2026 (XZ Utils, reviewdog→tj-actions, Aqua/Trivy, and litellm), detailing how attackers gained and maintained access (long‑term contributor accounts, CI workflow trigger abuse, tag repointing, direct PyPI uploads), the technical implants and exfiltration mechanisms (in‑build test‑file payloads, memory scraping via /proc/{PID}/mem, RSA/AES encrypted credential bundles, blockchain-hosted C2), mappings to MITRE ATT&CK, recurring remediation failures (forgotten bot tokens, mutable tags), detection engineering gaps, and prioritized operational mitigations (pin to commit SHAs, rotate bot tokens, monitor entrypoint sizes, block ICP domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.