Back Blog.Qualys The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
Malicious packages can steal cloud credentials during installation, before applications run.
Stolen credentials turn developer workstations and CI/CD pipelines into gateways to cloud resources.
Restrict installation scripts, minimize credential privileges, protect metadata access, and monitor cloud activity.
Containment requires revoking exposed credentials and investigating cloud activity beyond removing compromised packages.
Qualys TotalCloud connects cloud risk signals, while TruRisk helps prioritize exposures across multi-cloud environments
A Routine Package Install Can Become a Cloud Breach
A developer updates a dependency. The build passes. Soon after, cloud defenders see unfamiliar API calls made with valid credentials. The breach did not begin in the customer-facing application or production database. It began on the developer’s machine or in the build pipeline, where a trusted package gained access to cloud credentials.
This blog examines the anatomy of this threat class, dissects real-world incidents from 2025 and 2026, and provides a roadmap for cloud security teams to detect, respond to, and mitigate these attacks, with a focus on how Qualys TotalCloud can secure cloud metadata and resources across AWS, Azure, and GCP. The central argument is that once install-time malware reaches developer or CI credentials, a software supply chain incident. The central argument is that once install-time malware exposes credentials capable of accessing cloud resources, a software supply chain incident can become a cloud identity incident. Defenders must protect the developer environment and cloud infrastructure as one continuous attack surface.
Credentials in Developer and CI Environments Can Become a Cloud Gateway
A developer workstation or continuous integration and continuous delivery (CI/CD) runner is not just a coding machine. It is a nexus of credentials: AWS access keys, GitHub Personal Access Tokens (PATs), GCP service account tokens, Azure CLI credentials, npm publish tokens, SSH keys, Kubernetes kubeconfig files, and HashiCorp Vault tokens. These are often stored in plaintext in predictable locations (~/.aws/credentials, ~/.kube/config, .npmrc, .netrc) because developer tooling prioritizes convenience over adversarial resistance.
The npm ecosystem operates at enormous scale, with millions of packages and package downloads measured in the billions.[1][2] At that scale, a compromised package or maintainer account can potentially reach a large number of downstream developer and CI environments, creating an opportunity for credential harvesting.
Complete a 5-minute Cloud Maturity Questionnaire to receive a complementary detailed report.
The attacks observed between September 2025, and May 2026 follow a remarkably consistent kill chain, regardless of the ecosystem or threat actor involved. The repeated pattern matters more than any single package: trusted install-time code reaches credentials, valid credentials reach the cloud, and cloud access enables reconnaissance, persistence, and data theft.
The Shai-Hulud campaign emerged in September 2025 and compromised popular npm packages, including @ctrl/tinycolor. The injected worm scanned infected environments for cloud credentials and exfiltrated them to a public GitHub repository created under the victim’s own account. By November, a more aggressive variant had added backdoor capabilities and destructive behavior if credential theft failed.[3]
BufferZoneCorp: Persistence in the Build Host
A parallel campaign used a GitHub account named BufferZoneCorp to publish malicious Ruby gems and Go modules impersonating developer utilities. The Ruby packages harvested environment variables and credential files during installation. The Go modules redirected GOPROXY, disabled checksum verification, planted fake go wrappers, and in one case appended an SSH public key to ~/.ssh/authorized_keys. The lesson is not simply to vet another package ecosystem. Install-time code can modify the build host and the path of future commands.
TeamPCP: From Trusted Tooling to Cloud Account Takeover
TeamPCP compromised trusted developer and security tooling used in CI/CD environments, including Aqua Security’s Trivy scanner, Checkmarx’s KICS IaC scanner, the LiteLLM AI gateway/library, and a Telnyx communications library. The actor injected credential-stealing payloads into tools development teams inherently trust. Researchers reported that TeamPCP used stolen GitHub Personal Access Tokens to force-push malicious commits across repository version tags and bypassed GitHub’s secret masking by reading runner process memory directly.
The key lesson is that removing the compromised scanner would not, by itself, contain the incident. Once compromised code has executed in a CI/CD environment, credentials available to that pipeline should be treated as potentially exposed, and defenders should investigate the cloud activity those credentials could authorize.
Other Ecosystems Confirm the Same Credential-First Pattern
Between April 21 and 23, 2026, supply chain attacks hit npm, PyPI, and Docker Hub within 48 hours. The trojaned @bitwarden/cli package and compromised Checkmarx KICS images shared command-and-control infrastructure, harvested secrets, and propagated through publishing access. On May 28, 14 npm packages typosquatting OpenSearch and ElasticSearch libraries harvested cloud and pipeline secrets before using stolen npm publish tokens to infect additional maintainer-owned packages. The ecosystems differed, but the credential-first operating model did not.
Supporting MITRE ATT&CK Mapping
Potential Attack Path
Across these campaigns, the decisive advantage is install-time execution: malware runs in the developer or CI context before application controls engage. From there, campaigns harvest credentials, adapt to CI environments, encrypt exfiltrated data, and in some cases use stolen publishing access to propagate into other packages
Credential Theft Expands the Blast Radius Beyond Source Code
Once stolen credentials reach the cloud, the blast radius expands beyond source code to IAM roles, storage, secrets managers, serverless workloads, and Kubernetes. The speed of the documented pivots makes credential scope, not package removal, the first containment question.
Interrupt the Attack Path at Three Control Points
No single control covers this path. Teams need to reduce install-time trust, limit the authority available to the build, and detect what happens if valid credentials still reach the cloud.
1. Reduce Install-Time Trust
Use a private package registry (e.g., AWS CodeArtifact or JFrog Artifactory) with an approved package policy. Where operationally compatible, enable ignore-scripts=true in CI .npmrc to block package lifecycle scripts during installation; explicitly allow only required scripts where necessary. Pin dependencies with lockfiles and enforce lockfile integrity in pipelines. Use package-security and dependency-analysis tools such as Socket, Snyk, or GitHub Dependabot to identify newly introduced packages with suspicious or vulnerable behavior.
2. Limit the Credentials Available to Builds
Apply least-privilege to all CI/CD secrets — a build job compiling code should not hold AWS deployment credentials. Use short-lived OIDC-based credentials (GitHub Actions → AWS IAM) instead of long-lived stored keys. Treat any CI runner that executed an unvetted package as potentially compromised and rotate all secrets it had access to.
3. Detect and Constrain the Cloud Pivot
Enforce MFA on all IAM accounts. Use AWS SCPs or GCP Organization Policies to prevent compromised credentials from creating new admin roles or disabling audit logging. Enable CloudTrail, GCP Cloud Audit Logs, and Azure Monitor with immutable storage and real-time alerting on anomalous API calls. Monitor for unexpected GitHub-to-AWS OIDC trust creation.
Prepare for Extortion and Recovery
Given that actors like TeamPCP and ShinyHunters combine credential theft with data extortion, the following controls directly reduce extortion leverage:
The first response priority is credential and access scope: identify the credentials and tokens the affected host or runner could access, rotate or revoke them, and review cloud audit activity across the exposure window. Package removal alone is not containment.
Use Cloud Context to Find and Prioritize Post-Compromise Exposure
Qualys TotalCloud’s role in this attack path is to expose and prioritize the cloud risk created after credentials are stolen. TotalCloud is a unified Cloud-Native Application Protection Platform (CNAPP) that brings together cloud inventory, posture, identity, workload, runtime, and other security signals across supported cloud environments.
1. Establish What Exists and What Changed
TotalCloud continuously inventories cloud resources across AWS, Azure, and GCP, maintaining a comprehensive view of every resource created across your environment. Where newly provisioned IAM roles, EC2 instances, or S3 buckets carry overly permissive policies, TotalCloud can surface posture issues through its cloud security controls. For example, detecting IAM roles with wildcard “*” actions, publicly accessible S3 buckets, or roles missing boundary policies which allows security teams to identify policy drift before it can be exploited further.
2. Connect Exposed Authority to Reachable Assets
Identity and Access Risk
TotalCloud’s CIEM capabilities provide visibility into identity entitlements and can identify excessive or risky permissions across supported cloud identity resources. For example, AWS CIEM evaluates IAM-related resources and their permissions, while Azure CIEM provides entitlement visibility for supported identities and resources.
TotalCloud provides sensitive-data detection across supported cloud workloads, identifying exposed access keys, credentials, tokens, and certificates in AWS EC2 instances, Azure VMs, and GCP instances. It also supports detection of embedded keys and credentials during container image scans
Container and Kubernetes Posture
Qualys Container Security’s Kubernetes Posture Management (KSPM) evaluates Kubernetes posture, including RBAC-related controls that can identify excessive privileges, administrative roles, secret access, impersonation, and other risky permissions. These controls can help limit what an attacker can do even after obtaining a Kubernetes token.
3. Prioritize the Combined Risk
TruRisk correlates risk factors such as vulnerabilities, misconfigurations, identity risks, secrets, and runtime context to prioritize verified, attackable exposures using factors including exploitability, threat intelligence, asset criticality, and runtime context.
Close a High-Value Credential Path: Cloud Instance Metadata
One of the most underappreciated attack surfaces in the supply chain-to-cloud pivot is the Cloud Instance Metadata Service (IMDS) . A common credential-theft technique in this attack class is probing cloud instance metadata endpoints to obtain temporary credentials available to the compromised workload.
Enforce IMDSv2 via AWS Config rule ec2-imdsv2-check and SCP to prevent any instance launching with IMDSv1 enabled. IMDSv2’s required session-token PUT request blocks the simple GET-based probing used by most supply-chain malware.
Prefer Workload Identity Federation over long-lived service account key files for supported CI/CD and external workloads. This reduces reliance on static credentials and uses short-lived federated credentials instead.
Prefer Managed Identities with least-privilege Azure RBAC over long-lived credentials stored on CI runner VMs. Managed identities provide Azure resources with an automatically managed identity and allow workloads to obtain access tokens without storing credentials in application code.
Where CI/CD runners don’t legitimately query cloud metadata endpoints, egress filtering blocking 169.254.169.254 raises the bar for automated harvesting payloads.
Qualys TotalCloud’s continuous configuration assessment enforces IMDSv2 requirements across AWS EC2 instances and flags any still accepting IMDSv1 requests, directly closing one of the primary credential-harvesting vectors exploited in this campaign class.
Treat Developer Trust and Cloud Control as One Attack Surface
The attacks documented here show a recurring sequence: compromise a package or development tool, steal credentials available to the developer or CI environment, pivot into cloud resources, and potentially exfiltrate data or establish persistence. The European Commission incident and the UNC6426 campaign demonstrate that this is not merely a theoretical risk; compromised development environments can become a path to significant cloud impact.
Defenders must respond across that sequence. They must reduce install-time trust, limit standing credentials, rotate or revoke exposed credentials and secrets, review cloud activity, enforce metadata protections, and continuously prioritize identity, secrets, misconfiguration, and workload risk. Qualys TotalCloud provides the cloud visibility and prioritization layer through TruRisk across AWS, Azure, and GCP.
The supply chain is the new perimeter. Securing it means treating the developer environment and cloud infrastructure as a single, continuous attack surface.
Start Your Cloud Maturity Journey Today. Schedule a call with a cloud security expert.
Socket Research Team. “Mini Shai-Hulud Hits @antv Ecosystem, 639 Compromised npm Package Versions.” Socket.dev, May 19, 2026.
Kirill Boychenko. “Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI.” Socket.dev, May 1, 2026.
CISA. “Widespread Supply Chain Compromise Impacting npm Ecosystem.” September 23, 2025.
Trend Micro. “Shai-Hulud 2.0 Campaign Targets Cloud and Developer Ecosystems.” November 27, 2025.
CERT-EU. “European Commission Cloud Breach – Trivy Supply Chain.” March 2026.
Sophos. “Supply chain attacks hit Checkmarx and Bitwarden developer tools.” April 24, 2026.
GitGuardian. “No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours.” April 23, 2026.
The Hacker News. “UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours.” March 11, 2026.
Microsoft Security Blog. “Typosquatted npm packages used to steal cloud and CI/CD secrets.” May 28, 2026.
SANS Institute. “Axios NPM Supply Chain Compromise: Malicious Packages Deliver Remote Access Trojan.” April 1, 2026.
Arctic Wolf. “Wormable Malware Causing Supply Chain Compromise of npm Code Packages.” September 16, 2025.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
