Skip to main content

2 posts tagged with "nodejs"

View All Tags

Prevention Has a Ceiling: Designing CI Pipelines That Survive Being Breached

· 41 min read
Ivan Baha
Software Team Lead & Architect

A follow-up to The Silent Exfiltration.

That article described a pipeline in which a single malicious dependency could read every secret in the runner environment and post it to an arbitrary host, before any scan, on any branch, without a merge. It ended with a remediation ladder.

This one starts with an uncomfortable observation: organisations that climbed that ladder are still being hit. The largest software companies in the world, with dedicated supply chain security teams and eight-figure security budgets, had credentials compromised in this attack class in 2026. The conclusion is not that they were careless. The conclusion is that prevention has a ceiling, and above that ceiling a different approach is required – one that assumes the attacker is already executing within the build, and asks how much they obtain, how far they reach, and how long before anyone notices.

The Silent Exfiltration: Why Your CI Pipeline Is an Open Vault

· 17 min read
Ivan Baha
Software Team Lead & Architect

Modern CI/CD pipelines for Node.js applications show three worsening structural issues — secrets injected into the runner environment at the start of the pipeline, unrestricted npm lifecycle script execution during dependency installation, and open outbound network access on CI runners — which together enable silent, zero-alert credential exfiltration by any malicious package in the dependency tree. These findings are platform-independent: GitLab CI, GitHub Actions, and similar systems all have identical default insecure settings. The March 2026 compromise of the Axios npm package, a North Korean state-sponsored supply chain attack targeting a library with about 100 million weekly downloads, is discussed as a real case study confirming the large-scale exploitation of this attack surface.