Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
ResearchnpmGitHub ActionsOur summary
Palo Alto Networks' Unit 42 has published new research detailing how threat actors are shifting their focus from final software binaries to the foundational tools of the software development lifecycle (SDLC). The report highlights incidents such as the XZ Utils vulnerability (CVE-2024-3094) and the ChainDrop npm worm, which exploited preinstall hooks to harvest secrets from GitHub Actions runners and propagate via stolen tokens.
By targeting un-sandboxed environments like developer endpoints, CI/CD pipelines, and cloud container runtimes, attackers can bypass traditional application scans. Key affected areas include npm, GitHub Actions, and VS Code, where malicious extensions or scripts operate with user-level privileges. To mitigate these risks, the team recommends strict execution controls, such as ignoring install scripts and limiting credential lifetimes.
Below is the opening; the full story is at Palo Alto Unit 42.
From Palo Alto Unit 42
While supply chain threats have been quietly compounding over the past decade, the last 12–18 months have triggered a drastic shift in the scale and velocity of these attacks. Rather than just hunting for bugs in finished software, attackers are targeting the everyday tools and code developers rely on.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.