Developer Workstations Are Now Part of the Software Supply Chain

Supply chain attackers are not only trying to slip malicious code into trusted software They are trying to steal the access that makes trusted software possible Recently three separate campaigns hit npm PyPI and Docker Hub in a 48hour window and all three targeted secrets from developer environments and CICD pipelines including API keys cloud credentials SSH keys and tokens This is