The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches
Cybersecurity Classified by Officially
The attacks observed between September 2025, and May 2026 follow a remarkably consistent kill chain, regardless of the ecosystem or threat actor involved. The repeated pattern matters more than any single package: trusted install-time code reaches credentials, valid credentials reach the cloud, and cloud access enables reconnaissance, persistence, and data theft.
Shai-Hulud: Install-Time Theft at Ecosystem Scale
The Shai-Hulud campaign emerged in September 2025 and compromised popular npm packages, including @ctrl/tinycolor. The injected worm scanned infected environments for cloud credentials and exfiltrated them to a public GitHub repository created under the victim’s own account. By November, a more aggressive variant had added backdoor capabilities and destructive behavior if credential theft failed.[3]
By May 2026, Mini Shai-Hulud had shifted execution to the preinstall lifecycle hook, meaning credentials could be stolen even if the package installation was cancelled after the hook fired. The May 19 wave compromised 639 package versions across 323 packages in the @antv ecosystem, including echarts-for-react with 1.1 million weekly downloads. Its payloads targeted GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, KUBECONFIG, VAULT_TOKEN, and other cloud and infrastructure secrets. The practical lesson is that a user does not need to run the application for the cloud exposure to begin.[3][4]
BufferZoneCorp: Persistence in the Build Host
This is an extract. The publication continues at the source.
Read the original at the source: https://blog.qualys.com/vulnerabilities-threat-research/2026/09/28/developer-new-perimeter-supply-chain-cloud-breaches
Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Qualys — imported from official source
- Official source
- https://blog.qualys.com/feed RSS
- Imported
- September 28, 2026 15:00
- Versions
- 1 recorded
- Identity
https://blog.qualys.com/?p=42475