Skip to main content

3 posts tagged with "supply-chain"

View All Tags

Prevention Has a Ceiling: Designing CI Pipelines That Survive Being Breached

· 41 min read
Ivan Baha
Software Team Lead & Architect

A follow-up to The Silent Exfiltration.

That article described a pipeline in which a single malicious dependency could read every secret in the runner environment and post it to an arbitrary host, before any scan, on any branch, without a merge. It ended with a remediation ladder.

This one starts with an uncomfortable observation: organisations that climbed that ladder are still being hit. The largest software companies in the world, with dedicated supply chain security teams and eight-figure security budgets, had credentials compromised in this attack class in 2026. The conclusion is not that they were careless. The conclusion is that prevention has a ceiling, and above that ceiling a different approach is required – one that assumes the attacker is already executing within the build, and asks how much they obtain, how far they reach, and how long before anyone notices.

Tokenmaxxing and the Physics Bill — How the AI Compute Mania Is Repriced at Your Grid, Your Tap, and Your Subscription

· 24 min read
Ivan Baha
Software Team Lead & Architect

TL;DR: The software industry has gamified compute at the application layer while the physical layer hits hard limits. Three global chokepoints — hyperscale-captured memory supply, congested grids from Virginia to Dublin to Singapore, and collapsing flat-rate SaaS economics — combine to produce a single outcome: individual developers and households pay more to fund corporate "Tokenmaxxing" behaviour that produces no verifiable output. The Claudeonomics leaderboard, the PJM capacity auction, and the April 2026 GitHub Copilot signup suspension are all symptoms of the same structural contradiction.

The Silent Exfiltration: Why Your CI Pipeline Is an Open Vault

· 17 min read
Ivan Baha
Software Team Lead & Architect

Modern CI/CD pipelines for Node.js applications show three worsening structural issues — secrets injected into the runner environment at the start of the pipeline, unrestricted npm lifecycle script execution during dependency installation, and open outbound network access on CI runners — which together enable silent, zero-alert credential exfiltration by any malicious package in the dependency tree. These findings are platform-independent: GitLab CI, GitHub Actions, and similar systems all have identical default insecure settings. The March 2026 compromise of the Axios npm package, a North Korean state-sponsored supply chain attack targeting a library with about 100 million weekly downloads, is discussed as a real case study confirming the large-scale exploitation of this attack surface.