Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

StepSecurity
stepsecurity.io > blog > 2026-mid-year-update-on-pace-for-our-biggest-year-yet

2026 Mid-Year Update: On Pace for Our Biggest Year Yet

1+ day, 13+ hour ago   (590+ words) Six months ago, in our 2025 year-in-review, we shared that StepSecurity had grown ARR more than 5x for the second consecutive year, repeating the milestone we first announced in our 2024 year-in-review. We also committed to an ambitious 2026 roadmap: secure the developer machine,…...

StepSecurity
stepsecurity.io > case-studies > aerospike

How Aerospike Moved from Reactive to Proactive CI/CD Security with StepSecurity

2+ day, 13+ hour ago   (537+ words) Aerospike is the operational database that keeps applications predictable, even as conditions change, powering some of the world's largest enterprises. As a member of the leadership team, I oversee strategic decisions around how we build, secure, and scale our engineering…...

StepSecurity
stepsecurity.io > blog > sleepergem-compromised-rubygems-drop-persistent-backdoor

SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor

6+ day, 10+ hour ago   (755+ words) The releases were published straight to the registry with no matching commit or tag in the source projects. Two of the gems had been dormant for years before suddenly shipping new versions. StepSecurity ran every compromised version inside Harden-Runner in…...

StepSecurity
stepsecurity.io > blog > harden-runner-block-mode-now-available-for-macos-and-windows-github-hosted-runners

Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners

1+ week, 3+ day ago   (338+ words) Until now, Harden-Runner could answer "no" on Linux GitHub-hosted runners with egress-policy: block. On macOS and Windows GitHub-hosted runners, teams had audit mode: full visibility into outbound traffic, but no enforcement. With Harden-Runner v2.20.0, block mode is now supported on macOS…...

StepSecurity
stepsecurity.io > blog > introducing-device-policy-enforce-approved-vs-code-extensions-across-your-fleet

Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet

1+ week, 3+ day ago   (555+ words) The pattern is consistent: extensions run with the developer's privileges, and anyone on the team can install anything the marketplace offers. Most security teams have no control over that decision. Last year, Dev Machine Guard gave you visibility into every…...

StepSecurity
stepsecurity.io > blog > runtime-security-for-third-party-github-actions-runners

Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp

1+ week, 3+ day ago   (410+ words) Supply chain attacks do not check your runs-on label. When the Sha1-Hulud worm compromised prominent npm packages, the malicious code executed wherever npm install ran. When the Velora DEX SDK compromise dropped a macOS backdoor through npm, it did not…...

Google News
stepsecurity.io > blog > announcing-dependabot-configuration-enhancements-cooldown-and-group-support

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support

1+ week, 4+ day ago   (826+ words) StepSecurity now supports cooldown and group attributes for Dependabot configuration management. These additions give organizations precise control over how dependency updates are batched and how frequently they arrive, across npm, pip, Docker, GitHub Actions, and other Dependabot supported ecosystems. A…...

StepSecurity
stepsecurity.io > blog > compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm

Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories

1+ week, 4+ day ago   (596+ words) The attacker pushed a series of commits between 07:51 and 08:28 UTC. The key events: We ran the payload chain in a monitored, isolated GitHub Actions job wrapped with Harden-Runner to capture the actual runtime network behavior of the second-stage sync.js…...

Google News
stepsecurity.io > blog > jscrambler-npm-package-publishes-malicious-preinstall-binary

jscrambler npm package publishes malicious preinstall binary

2+ week, 10+ hour ago   (595+ words) If you installed jscrambler 8.14.0: Treat the host as compromised. Downgrade to 8.13.0, rotate every credential that was logged into a browser on that machine, and audit any crypto wallet browser extensions for unauthorized activity. jscrambler is the official npm CLI for…...

StepSecurity
stepsecurity.io > blog > mass-npm-supply-chain-attack-20-leo-platform-packages-compromised

Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

1+ mon, 19+ hour ago   (377+ words) The following 20 packages are confirmed malicious at the listed versions. All were published simultaneously by an unauthorized actor who gained access to the Leo Platform maintainer credentials. On June 3, 2026 we published a detailed technical analysis of the Miasma campaign, which…...