TL;DR: Unosecur says March 2026 compromises of Trivy’s signed releases let attackers steal CI/CD pipeline credentials and use valid logins to reach Cisco repositories, cloud assets, and the European Commission’s backend, affecting more than 70 Union entities. Identity blast radius, not exploit volume, now determines supply chain damage.
At a glance
What this is: This analysis argues that CI/CD credential theft, not software exploitation, drove two linked supply-chain compromises that let attackers authenticate into trusted environments and move laterally through repositories, cloud accounts, and downstream systems.
Why it matters: It matters because IAM, PAM, and NHI programmes have to govern pipeline identities as high-value access paths, or valid credentials will continue to outrun traditional exploit-focused detection.
👉 Read Unosecur's analysis of CI/CD credential theft and supply chain identity risk
Context
CI/CD pipeline credentials are machine identities, not just implementation details. When a build or scan environment can read tokens, cloud keys, and access secrets, the pipeline becomes part of the enterprise trust boundary and the blast radius depends on what those identities can reach.
This article examines two March 2026 compromises that used stolen pipeline credentials to log into trusted systems instead of exploiting software flaws. The pattern is a governance failure in supply chains: authenticated access is being granted to infrastructure that was never designed to be treated as a privileged identity plane.
For IAM and NHI teams, the lesson is that development tooling, cloud keys, and repository tokens now need the same lifecycle scrutiny as other privileged non-human identities. The issue is not whether a scanner runs, but what identities its execution context can expose and where those identities are allowed to operate.
Key questions
Q: What breaks when CI/CD workflow actions or build credentials are tampered with?
A: A poisoned workflow action can turn trusted automation into a credential-exfiltration path, especially when runners hold deployment tokens, cloud keys, or signing material. The break point is not just the build itself. It is the assumption that a pinned dependency or reusable action is stable. Teams should treat build systems as high-trust NHI environments and verify provenance continuously.
Q: Why do stolen pipeline secrets create such a large blast radius?
A: Stolen pipeline secrets create a large blast radius because they often carry permissions that were designed for convenience, not containment. If a single token can access code, cloud infrastructure, and adjacent services, every authorised action after theft looks legitimate. The risk rises sharply when the same identity is reused across environments or left active too long.
Q: How do security teams know whether CI/CD risk gates are actually working?
A: Look for enforced outcomes, not just alert volume. A working gate blocks critical issues, records every exception, identifies the approver, and preserves release evidence that can be audited later. If findings do not change release behaviour, the gate is advisory, not controlling.
Q: What should teams do when a CI/CD credential is exposed?
A: Revoke the token, validate the affected pipeline and artifact chain, and confirm whether the credential was used for deployment or build access. Then rotate any related secrets, review recent pipeline changes, and verify that protected environments and approvals still block unauthorized release activity.
Technical breakdown
How CI/CD pipeline credentials become a trusted attack path
CI/CD systems often inherit broad access because they must fetch code, run scans, sign artifacts, and talk to cloud services in one flow. That convenience turns tokens, keys, and secrets into a concentrated identity layer. If a malicious dependency or compromised release executes inside the build context, it does not need to break encryption or bypass authentication. It simply reads the credentials already present in memory, environment variables, secret stores, or mounted files, then reuses them elsewhere as valid identities.
Practical implication: treat build-time secrets as privileged NHI credentials, not disposable automation details.
Why valid credentials evade traditional detection
Most security monitoring is still tuned to malware, exploits, and impossible travel for human users. CI/CD credential theft looks ordinary because the attacker is using authorised mechanisms: API calls, repository clones, cloud logins, and access-key creation. That means telemetry has to shift from perimeter alerts to identity behaviour, including token issuance, key creation, privilege scope, and access patterns across pipelines, cloud accounts, and SaaS services. The attack is visible only when the expected behaviour of the identity is defined and monitored.
Practical implication: baseline expected behaviour for service accounts and pipeline tokens, then alert on scope changes and unusual access paths.
How blast radius expands after a single credential is stolen
A single pipeline credential can map to many downstream systems when permissions are inherited or reused across environments. In the article’s examples, stolen build secrets led to repository cloning, cloud activity, data extraction, and persistent access creation. The technical issue is not just secret exposure. It is that one credential often carries enough authority to cross trust zones, and once that authority is valid, each additional hop looks like legitimate operations to the systems involved.
Practical implication: reduce cross-environment permission chaining and separate pipeline access from production and customer data paths.
Threat narrative
Attacker objective: The attacker objective was to convert trusted pipeline access into broad authenticated reach across source code, cloud infrastructure, and sensitive organisational data.
- Entry occurred when attackers inserted credential-stealing malware into Trivy’s official releases and the compromised scanner ran inside CI/CD pipelines.
- Credential harvesting followed as the malware collected tokens, cloud keys, and access secrets present in the build environment.
- Escalation and lateral movement occurred when those valid credentials were reused to reach repositories, cloud accounts, and affiliated infrastructure.
- Impact was achieved through repository cloning, cloud activity, persistent access creation, and large-scale data exposure across enterprise and public-sector environments.
Breaches seen in the wild
- Cisco DevHub breach 2024: A misconfigured script left non-public files on Cisco's DevHub; IntelBroker took them and claimed reuse of hard-coded SSH credentials.
- Secrets in VS Code extensions 2025: Wiz found 550+ secrets in VS Code extensions, including publishing tokens able to push malicious updates to about 150,000 installs.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Pipeline credentials are now production identities. CI/CD secrets are often treated as temporary implementation artefacts, but this article shows they function as high-value non-human identities with direct business impact. When a build context can reach repositories, cloud accounts, and SaaS platforms, the pipeline itself becomes part of the privileged access plane. Practitioners should govern it accordingly, because the compromise path is no longer theoretical.
Identity blast radius is the real supply chain control metric. The central question is not whether a scanner or package is trusted, but how far the credentials inside that execution context can travel once stolen. The Cisco and European Commission cases show that damage is determined by permission chaining, not by exploit sophistication. That makes blast radius analysis a board-level identity concern, not a tooling detail.
Credential theft in CI/CD is a governance failure, not a point-in-time breach. The article shows a pattern of fragmented visibility, overbroad access, and incomplete rotation across machine identities. Those conditions let an upstream compromise cascade into multiple downstream environments without any security control meaningfully breaking the chain. The implication is that NHI governance has to cover build systems, cloud keys, and repository tokens as one lifecycle.
Secret sprawl in delivery pipelines creates reusable trust debt. Each token copied into a pipeline, scan job, or automation step adds another place where the same identity can be replayed later. That debt accumulates across open-source tooling, cloud integrations, and release processes until one compromise can unlock many systems at once. Practitioners should treat this as a structural exposure pattern, not an isolated incident.
Behavioural monitoring has to move from users to machine identities. The attacker activity in this article looked legitimate to systems that were built to detect anomalous human logins or malware signatures. Machine identities need their own baselines for token use, key creation, repository access, and cross-account movement. Without those baselines, valid credentials will remain operationally invisible even when they are clearly being abused.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — What are Non-Human Identities
What this signals
Identity blast radius is becoming the most useful way to measure supply-chain exposure. A build system that can authenticate into repositories, cloud accounts, and SaaS platforms turns one stolen credential into many downstream paths, so practitioners need to understand reach before they can reduce risk.
The control gap is not just secret storage. It is the combination of over-privileged machine identities, shared trust across delivery stages, and weak behavioural monitoring for non-human actors. Once those conditions exist, a compromised pipeline can look fully normal while it is moving valid access through the environment.
For practitioners
- Map pipeline credentials to downstream blast radius Inventory every CI/CD token, cloud key, and repository secret, then document exactly which accounts, services, and environments each one can reach.
- Separate build-time and production access Remove shared credentials between delivery systems and production cloud accounts so a compromised build job cannot automatically inherit customer-facing or management privileges.
- Rotate and revoke credentials after any build compromise Treat compromise of a scanner, dependency, or release artifact as a trigger to rotate pipeline secrets, cloud keys, and repository tokens that may have been exposed.
- Detect abnormal machine identity behaviour Baseline repository cloning, new access-key creation, and unusual cloud API activity so identity threat detection can flag valid credentials used outside expected scope.
Key takeaways
- CI/CD compromise becomes a supply-chain identity problem when stolen credentials can authenticate into repositories, cloud platforms, and affiliated services.
- The article shows that the damage followed permission scope, not exploit sophistication, which is why identity blast radius matters more than the initial malware event.
- Teams that can narrow machine-identity reach, separate build and production access, and monitor token behaviour are better positioned to contain the next compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article centres on pipeline secrets stolen from build environments. |
| NHI-05 — Overprivileged NHI | The damage came from pipeline identities with more reach than the task required. | |
| NHI-07 — Long-Lived Secrets | Persistent access and delayed rotation are central to the compromise chain. | |
| Recommendation — Scan CI/CD environments for exposed secrets and revoke any credential that may have leaked. Reduce pipeline privilege scope so build identities cannot reach production or customer systems unnecessarily. Shorten secret lifetimes and remove any machine credential that can survive a compromise window. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The incident depends on weak lifecycle control of authenticators and tokens. |
| Recommendation — Apply authenticator lifecycle controls to rotate, revoke, and reissue pipeline credentials rapidly. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The attacker collected credentials and used them to move across systems. |
| Recommendation — Map the compromise to credential access and lateral movement to prioritize containment and detection. | ||
Key terms
- CI/CD Credential Broker: A CI/CD system that does more than build and deploy because it also stores or issues credentials for cloud and application access. In practice, this creates a hidden identity tier inside delivery infrastructure, where compromise of the pipeline can expose downstream permissions.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Secrets Sprawl: The uncontrolled proliferation of sensitive credentials, API keys, tokens, passwords, certificates, across codebases, cloud environments, CI/CD pipelines, and configuration files. In 2024, over 50 million leaked secrets were found on the dark web.
What's in the full article
Unosecur's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step breakdown of how the Trivy compromise exposed pipeline tokens, cloud keys, and access secrets
- Named-entity analysis of the Cisco and European Commission compromise paths and their different downstream impacts
- Details on the persistent access technique used in the European Commission case, including key creation from an existing account
- Unosecur's view of how its identity visibility and detection layer maps to CI/CD and cloud environments
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on May 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org