Modern CI/CD pipelines for Node.js applications show three worsening structural issues — secrets injected into the runner environment at the start of the pipeline, unrestricted npm lifecycle script execution during dependency installation, and open outbound network access on CI runners — which together enable silent, zero-alert credential exfiltration by any malicious package in the dependency tree. These findings are platform-independent: GitLab CI, GitHub Actions, and similar systems all have identical default insecure settings. The March 2026 compromise of the Axios npm package, a North Korean state-sponsored supply chain attack targeting a library with about 100 million weekly downloads, is discussed as a real case study confirming the large-scale exploitation of this attack surface.
Building similarity graph...
Analyzing shared references across papers
Loading...
Ivan Baha
Building similarity graph...
Analyzing shared references across papers
Loading...
Ivan Baha (Tue,) studied this question.
www.synapsesocial.com/papers/69d893eb6c1944d70ce04e75 — DOI: https://doi.org/10.5281/zenodo.19454084