By NHI Mgmt Group Editorial TeamBased on Oasis Security: “When Supply Chain Attacks Meet NHI Sprawl” (May 1, 2026)

TL;DR: Aqua’s incomplete rotation after the Trivy compromise left residual access that TeamPCP later used to expand a supply-chain cascade into LiteLLM, Mercor, and thousands of downstream targets, according to Oasis Security. The pattern shows that credential rotation without inventory, dependency mapping, and verification is not containment; it is deferred re-compromise.


At a glance

What this is: This analysis argues that the Aqua Trivy compromise became a broad supply chain cascade because residual NHI access survived rotation and enabled further compromise.

Why it matters: It matters because IAM and NHI teams need to treat leaked credentials as lifecycle and blast-radius problems, not just secret-rotation tasks.


Context

Supply chain attacks against software tooling often succeed because they inherit whatever identity sprawl already exists inside the development and delivery stack. In this case, the critical problem is not only the initial compromise, but the residual access that remains after an organisation believes rotation has closed the door.

For NHI governance, that means the real control gap is lifecycle completeness: inventory, dependency mapping, validation, and offboarding of non-human identities. If those elements are missing, a rotated credential can still leave enough access to extend the breach rather than contain it.

The article uses the Trivy to LiteLLM to Mercor chain as a concrete example of why NHI exposure turns a supply chain incident into a multi-target cascade. That pattern is typical in modern CI/CD and cloud environments, where machine credentials outnumber human accounts and are often only partially governed.


Key questions

Q: What breaks when a leaked NHI credential is rotated but not fully revoked?

A: The original access path can remain usable if any downstream system still trusts the old secret, cached token, or surviving service account. That means the breach is only partially contained, and an attacker can return through the same identity path. In practice, incomplete revocation turns a response action into a delayed re-compromise.

Q: Why do supply chain attacks become larger when NHI sprawl is unmanaged?

A: Because the initial compromise is only the entry point. Unmanaged machine identities give attackers more places to validate stolen secrets, more services to reach, and more hidden dependencies to exploit. The result is a small foothold turning into a wide blast radius across CI/CD, cloud, and data systems.

Q: How do security teams know whether NHI rotation is actually working?

A: Rotation is working only if teams can show that every exposed credential was found, replaced, and validated against downstream dependencies without disrupting production. If the environment still contains unknown service accounts or untracked tokens, rotation is partial at best. The useful signal is complete coverage, not just a completed change ticket.

Q: Who is accountable for closing exposed NHI access after a supply chain incident?

A: Accountability sits with the teams that own the credential, the downstream service that consumes it, and the incident responders coordinating revocation. In regulated environments, the broader governance function must ensure ownership, lifecycle records, and verification evidence exist before the incident is declared closed.


Technical breakdown

How residual NHI access extends a supply chain compromise

Supply chain attacks often start with a single trusted integration point, but the damage comes from the identities already embedded in that environment. In this case, TeamPCP exploited a GitHub Actions workflow, stole a privileged token, and later used access that had not been fully severed. Once an attacker can validate credentials and enumerate downstream systems, the compromise stops being about the original vector and becomes about the identity estate behind it. The technical lesson is that rotated secrets can remain operational if the revocation path is incomplete or consumers still trust cached credentials.

Practical implication: build revocation checks that confirm every consumer of a compromised NHI credential has actually been cut off.

Why blast radius depends on inventory and dependency mapping

Blast radius is not defined by the stolen credential alone. It is defined by the services, clusters, databases, and secret stores that the credential can reach, plus the hidden dependencies that break when access changes. The article shows this with Mercor’s VPN credential, which unlocked network access, and with the broader campaign that touched IAM roles, ECS clusters, and databases. Without a live dependency map, security teams cannot tell whether rotation is safe, whether migration is complete, or whether a surviving path still exists in production.

Practical implication: maintain a dependency map for every high-risk NHI so revocation decisions can be made with service impact in view.

Why NHI lifecycle controls fail when credentials outlive their purpose

A credential that was created for a narrow purpose but never deprovisioned is already a future incident path. The post shows attackers filtering harvested secrets for validity, which means stale credentials create unnecessary attack surface long after the original business need is gone. In NHI terms, this is an offboarding failure, not just a rotation failure. The issue is not whether the credential exists, but whether it still has a legitimate owner, a current consumer, and a verifiable purpose in the environment.

Practical implication: tie every secret to an owner, purpose, and expiry so unused machine credentials can be removed before attackers find them.


Threat narrative

Attacker objective: The objective was to turn one supply chain foothold into large-scale downstream access and data theft by harvesting and reusing non-human credentials.

  1. Entry occurred through a misconfigured GitHub Actions workflow in the Aqua Trivy environment, where TeamPCP stole a privileged access token.
  2. Credential harvesting followed when the attackers used residual access after incomplete rotation to publish malicious releases and collect additional secrets from trusted CI/CD tooling.
  3. Escalation and lateral movement happened as the campaign validated credentials, enumerated cloud environments, and expanded into LiteLLM, Mercor, and other targets.
  4. Impact was broad exfiltration and compromise, including the Mercor breach and the theft of cloud keys, VPN access, database passwords, and other non-human credentials.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

NHI sprawl is the force multiplier that turns supply chain compromise into cascading breach scope. The article shows that the initial vector changed, but the outcome kept expanding because machine credentials already had reach across CI/CD, cloud, and secret management layers. That is why supply chain security and NHI governance cannot be separated in practice. Practitioners should treat every trusted automation path as part of the blast-radius model.

Rotation alone is not containment when identity inventory is incomplete. The Aqua example shows a familiar governance assumption breaking in real time: organisations assume they can rotate what they know exists, but they cannot close what they have not discovered, mapped, or verified. This is a lifecycle failure, not a tooling failure. The implication is that offboarding, ownership, and dependency visibility must be treated as part of the security control itself.

Blast-radius control is the named concept this incident makes unavoidable. A compromised credential is only one problem; the larger problem is how far it can travel before it is invalidated. In this article, the distance between rotation and verification is what allowed residual access to become a multi-target campaign. Practitioners need to think in terms of reach, consumers, and downstream trust, not just secret status.

Credential hygiene without behavioural validation leaves a blind spot in modern CI/CD environments. The attackers did not need exotic techniques once they had working credentials and a trusted automation surface. That means governance has to ask not only whether a secret is active, but whether its use still matches expected identity behaviour. The practical conclusion is that non-human identity oversight must include context, not just inventory.

Supply chain remediation increasingly depends on identity governance discipline, not only code or pipeline controls. The article aligns with OWASP-NHI, NIST-CSF, and MITRE ATT&CK because the failure spans credential leakage, privilege reach, and lateral movement. Teams that still treat machine identities as a secondary control domain will keep discovering that downstream compromise is easier than upstream prevention. The field should read this as a governance problem with security consequences, not the other way around.

From our research library:

What this signals

Blast-radius control: When a supply chain compromise reaches non-human identities, the security question shifts from where the attacker entered to how far the credential estate can carry them. Inventory, dependency mapping, and offboarding become the difference between a contained event and a cascading breach.

The operational signal is clear: teams that can verify which machine credentials still work, where they are consumed, and what they can reach will recover faster than teams that only know a secret was exposed. That is why identity-aware secret handling belongs in the incident response path, not beside it.


For practitioners

  • Map every high-risk NHI credential to its consumers Build a live inventory that ties each privileged secret to its owner, downstream systems, and approval history so you can see what rotation will actually affect.
  • Verify rotation before closing the incident Treat revocation as incomplete until every credential in the affected blast radius has been invalidated and every dependent service has moved to a new secret.
  • Decommission stale machine credentials aggressively Remove credentials that no longer have a current business purpose, especially those created for temporary workflows, legacy integrations, or dormant CI paths.
  • Baseline normal NHI behaviour in CI/CD Watch for unusual enumeration, secret access, or cross-environment calls from identities that normally touch only a narrow set of pipelines or resources.
  • Separate secret discovery from remediation ownership Make sure the team that detects exposed secrets can also route them to the identity owner who can revoke, migrate, and confirm closure without delay.

Key takeaways

  • The article frames the real risk as unmanaged NHI reach, not just the original supply chain entry point.
  • The Aqua-to-Mercor chain shows how residual access can survive rotation and expand a breach across multiple targets.
  • The control gap is verified offboarding and dependency visibility, because rotation without proof of closure leaves the blast radius intact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article centers on leaked and residual machine secrets after supply chain compromise.
NHI-01 — Improper OffboardingResidual access after rotation is an offboarding failure for compromised machine identities.
NHI-05 — Overprivileged NHIThe campaign succeeded because privileged tokens and broad NHI reach amplified the blast radius.
Recommendation — Scan for exposed NHI secrets and revoke any residual credentials that survive an incident. Treat offboarding as complete only after every NHI consumer and trust path is confirmed closed. Reduce privilege scope for machine identities so stolen credentials cannot traverse broad environments.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about knowing and controlling entitlements that remain after compromise.
Recommendation — Review and constrain NHI entitlements so revoked credentials do not retain effective access.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe attack chain moved from credential theft into broader access and expansion.
Recommendation — Map the incident to credential access and lateral movement to prioritise detection and containment controls.

Key terms

  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Identity-aware Secret Scanning: Secret scanning that links an exposed credential to the identity that uses it, rather than treating the secret as a standalone string. The goal is to determine whether the credential is live, who owns it, and how to remediate it without breaking the systems that depend on it.
  • Residual Access: Residual access is any permission, token, account, or data path that continues to work after a user should no longer have access. It is a common failure mode in SaaS-heavy environments because deprovisioning one system does not automatically shut down all downstream connections.
  • Dependency Mapping: Dependency mapping is the process of identifying which systems, services, and workflows rely on a given identity or secret. It is critical for NHI rotation because teams need to know what will fail before they change credentials. Without it, security teams often delay remediation to avoid outages.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org