StepSecurity detected and blocked a PR that compromised a downstream NPM package introduced by a new dependency.
Published
Signal category
Technology & Infrastructure
Quote
“StepSecurity detected and blocked the PR. The compromised package never entered the codebase beyond a draft PR.”
— StepSecurity team
Company
StepSecurity
Prevent, Detect, and Respond to Software Supply Chain Attacks
- Industry
- Computer and Network Security
- Location
- Seattle, US
- Company size
- 25 employees
StepSecurity secures the software supply chain end to end, across developer machines, code repos, and CI/CD pipelines. We help teams prevent, detect, and respond to supply chain attacks at every stage of software delivery, from the first line of code a developer writes to the final build that ships. On developer machines, StepSecurity monitors AI coding agents, IDE extensions, and packages, and detects compromised dependencies before they spread. In code repos, it raises automated security pull requests, enforces branch protection, and flags compromised dependencies on every pull request. In CI/CD pipelines, StepSecurity Harden-Runner enforces runner-level network egress controls, detects anomalies in every workflow step, and provides secure drop-in replacements for third-party actions. StepSecurity is powered by a dedicated threat intelligence team that has detected and disclosed some of the largest supply chain attacks in the industry, including the tj-actions/changed-files compromise, the axios npm attack, and the Trivy compromise. Over 15,000 open-source projects, including those from the Cybersecurity and Infrastructure Security Agency (CISA), Google, Microsoft, Datadog, Kubernetes, Node.js, and Ruby, use StepSecurity. Our enterprise tier is deployed at customers in the crypto, healthcare, and cybersecurity industries. The StepSecurity platform secures more than 35,000,000 CI/CD job runs every week.
Founded 2021