The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches 

Imported from official source

Cybersecurity Classified by Officially

The attacks observed between September 2025, and May 2026 follow a remarkably consistent kill chain, regardless of the ecosystem or threat actor involved. The repeated pattern matters more than any single package: trusted install-time code reaches credentials, valid credentials reach the cloud, and cloud access enables reconnaissance, persistence, and data theft. 

Shai-Hulud: Install-Time Theft at Ecosystem Scale 

The Shai-Hulud campaign emerged in September 2025 and compromised popular npm packages, including @ctrl/tinycolor. The injected worm scanned infected environments for cloud credentials and exfiltrated them to a public GitHub repository created under the victim’s own account. By November, a more aggressive variant had added backdoor capabilities and destructive behavior if credential theft failed.[3] 

By May 2026, Mini Shai-Hulud had shifted execution to the preinstall lifecycle hook, meaning credentials could be stolen even if the package installation was cancelled after the hook fired. The May 19 wave compromised 639 package versions across 323 packages in the @antv ecosystem, including echarts-for-react with 1.1 million weekly downloads. Its payloads targeted GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, KUBECONFIG, VAULT_TOKEN, and other cloud and infrastructure secrets. The practical lesson is that a user does not need to run the application for the cloud exposure to begin.[3][4] 

BufferZoneCorp: Persistence in the Build Host 

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/vulnerabilities-threat-research/2026/09/28/developer-new-perimeter-supply-chain-cloud-breaches

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 28, 2026 15:00
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42475

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.