Back to Feed
Supply ChainSep 28, 2026

The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

Malicious packages steal cloud credentials during installation, turning dev environments into cloud gateways.

Summary

Attackers are exploiting the software supply chain by embedding malicious code in packages that steal cloud credentials during installation. These stolen credentials, often stored insecurely on developer workstations or CI/CD pipelines, then serve as a gateway to cloud resources, enabling reconnaissance, persistence, and data theft. Defenders must treat developer environments and cloud infrastructure as a single attack surface, implementing controls like restricting installation scripts and monitoring cloud activity.

Full text

Table of ContentsKey TakeawaysA Routine Package Install Can Become a Cloud BreachCredentials in Developer and CI Environments Can Become a Cloud GatewayShai-Hulud: Install-Time Theft at Ecosystem ScaleBufferZoneCorp: Persistence in the Build HostTeamPCP: From Trusted Tooling to Cloud Account TakeoverOther Ecosystems Confirm the Same Credential-First PatternSupporting MITRE ATT&CK MappingPotential Attack PathInstall-Time Execution Makes Developer Trust the Attackers AdvantageCredential Theft Expands the Blast Radius Beyond Source CodeInterrupt the Attack Path at Three Control PointsPrepare for Extortion and RecoveryUse Cloud Context to Find and Prioritize Post-Compromise ExposureClose a High-Value Credential Path: Cloud Instance MetadataTreat Developer Trust and Cloud Control as One Attack Surface Key Takeaways Malicious packages can steal cloud credentials during installation, before applications run. Stolen credentials turn developer workstations and CI/CD pipelines into gateways to cloud resources. Restrict installation scripts, minimize credential privileges, protect metadata access, and monitor cloud activity. Containment requires revoking exposed credentials and investigating cloud activity beyond removing compromised packages. Qualys TotalCloud connects cloud risk signals, while TruRisk helps prioritize exposures across multi-cloud environments A Routine Package Install Can Become a Cloud Breach A developer updates a dependency. The build passes. Soon after, cloud defenders see unfamiliar API calls made with valid credentials. The breach did not begin in the customer-facing application or production database. It began on the developer’s machine or in the build pipeline, where a trusted package gained access to cloud credentials. This blog examines the anatomy of this threat class, dissects real-world incidents from 2025 and 2026, and provides a roadmap for cloud security teams to detect, respond to, and mitigate these attacks, with a focus on how Qualys TotalCloud can secure cloud metadata and resources across AWS, Azure, and GCP. The central argument is that once install-time malware reaches developer or CI credentials, a software supply chain incident. The central argument is that once install-time malware exposes credentials capable of accessing cloud resources, a software supply chain incident can become a cloud identity incident. Defenders must protect the developer environment and cloud infrastructure as one continuous attack surface. Credentials in Developer and CI Environments Can Become a Cloud Gateway A developer workstation or continuous integration and continuous delivery (CI/CD) runner is not just a coding machine. It is a nexus of credentials: AWS access keys, GitHub Personal Access Tokens (PATs), GCP service account tokens, Azure CLI credentials, npm publish tokens, SSH keys, Kubernetes kubeconfig files, and HashiCorp Vault tokens. These are often stored in plaintext in predictable locations (~/.aws/credentials, ~/.kube/config, .npmrc, .netrc) because developer tooling prioritizes convenience over adversarial resistance. The npm ecosystem operates at enormous scale, with millions of packages and package downloads measured in the billions.[1][2] At that scale, a compromised package or maintainer account can potentially reach a large number of downstream developer and CI environments, creating an opportunity for credential harvesting. Take the SurveyComplete a 5-minute Cloud Maturity Questionnaire to receive a complementary detailed report.Take the Survey Recent Campaigns Show the Same Package-to-Cloud Kill Chain The attacks observed between September 2025, and May 2026 follow a remarkably consistent kill chain, regardless of the ecosystem or threat actor involved. The repeated pattern matters more than any single package: trusted install-time code reaches credentials, valid credentials reach the cloud, and cloud access enables reconnaissance, persistence, and data theft. Shai-Hulud: Install-Time Theft at Ecosystem Scale The Shai-Hulud campaign emerged in September 2025 and compromised popular npm packages, including @ctrl/tinycolor. The injected worm scanned infected environments for cloud credentials and exfiltrated them to a public GitHub repository created under the victim’s own account. By November, a more aggressive variant had added backdoor capabilities and destructive behavior if credential theft failed.[3] By May 2026, Mini Shai-Hulud had shifted execution to the preinstall lifecycle hook, meaning credentials could be stolen even if the package installation was cancelled after the hook fired. The May 19 wave compromised 639 package versions across 323 packages in the @antv ecosystem, including echarts-for-react with 1.1 million weekly downloads. Its payloads targeted GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, KUBECONFIG, VAULT_TOKEN, and other cloud and infrastructure secrets. The practical lesson is that a user does not need to run the application for the cloud exposure to begin.[3][4] BufferZoneCorp: Persistence in the Build Host A parallel campaign used a GitHub account named BufferZoneCorp to publish malicious Ruby gems and Go modules impersonating developer utilities. The Ruby packages harvested environment variables and credential files during installation. The Go modules redirected GOPROXY, disabled checksum verification, planted fake go wrappers, and in one case appended an SSH public key to ~/.ssh/authorized_keys. The lesson is not simply to vet another package ecosystem. Install-time code can modify the build host and the path of future commands. TeamPCP: From Trusted Tooling to Cloud Account Takeover TeamPCP compromised trusted developer and security tooling used in CI/CD environments, including Aqua Security’s Trivy scanner, Checkmarx’s KICS IaC scanner, the LiteLLM AI gateway/library, and a Telnyx communications library. The actor injected credential-stealing payloads into tools development teams inherently trust. Researchers reported that TeamPCP used stolen GitHub Personal Access Tokens to force-push malicious commits across repository version tags and bypassed GitHub’s secret masking by reading runner process memory directly. The key lesson is that removing the compromised scanner would not, by itself, contain the incident. Once compromised code has executed in a CI/CD environment, credentials available to that pipeline should be treated as potentially exposed, and defenders should investigate the cloud activity those credentials could authorize. Other Ecosystems Confirm the Same Credential-First Pattern Between April 21 and 23, 2026, supply chain attacks hit npm, PyPI, and Docker Hub within 48 hours. The trojaned @bitwarden/cli package and compromised Checkmarx KICS images shared command-and-control infrastructure, harvested secrets, and propagated through publishing access. On May 28, 14 npm packages typosquatting OpenSearch and ElasticSearch libraries harvested cloud and pipeline secrets before using stolen npm publish tokens to infect additional maintainer-owned packages. The ecosystems differed, but the credential-first operating model did not. Supporting MITRE ATT&CK Mapping ATT&CK ID Technique Observed Behavior T1195.001 Compromise Software Dependencies and Development Tools Malicious npm, PyPI, RubyGems, Go modules T1204.005 User Execution: Malicious Library Malicious libraries triggered during package installation T1036.005 Match Legitimate Resource Name or Location Typosquatting, e.g. @bitwarden/cli, plausible package branding T1059.004 Command and Scripting Interpreter: Unix Shell Shell scripts and Bun-based payloads executing in CI runners T1552.001 Unsecured Credentials: Credentials in Files Harvesting ~/.aws/credentials, .npmrc, .netrc, SSH keys T1552.004 Unsecured Credentials: Private Keys SSH private key exfiltration T1552.005 Unsecured Credentials: Cloud Instance Metadata API IMDS probing for EC2 instance credentials T1098.004 Account Manipulation: SSH Authorized Keys Append

Entities

Shai-Hulud (campaign)BufferZoneCorp (campaign)TeamPCP (campaign)CI/CD (technology)Qualys TotalCloud (product)cloud metadata (technology)