CVE Tools

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Palo Alto Unit 42By Yaron Avital6 min read

ResearchnpmGitHub Actions

Our summary

Palo Alto Networks' Unit 42 has published new research detailing how threat actors are shifting their focus from final software binaries to the foundational tools of the software development lifecycle (SDLC). The report highlights incidents such as the XZ Utils vulnerability (CVE-2024-3094) and the ChainDrop npm worm, which exploited preinstall hooks to harvest secrets from GitHub Actions runners and propagate via stolen tokens.

By targeting un-sandboxed environments like developer endpoints, CI/CD pipelines, and cloud container runtimes, attackers can bypass traditional application scans. Key affected areas include npm, GitHub Actions, and VS Code, where malicious extensions or scripts operate with user-level privileges. To mitigate these risks, the team recommends strict execution controls, such as ignoring install scripts and limiting credential lifetimes.

Read at Palo Alto Unit 42

Below is the opening; the full story is at Palo Alto Unit 42.

From Palo Alto Unit 42

While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on.…

Continue at Palo Alto Unit 42

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store