Join our Newsletter — 33% off our NHI Course

NHI sprawl in supply chain attacks: what teams need to fix

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Aqua’s incomplete rotation after the Trivy compromise left residual access that TeamPCP later used to expand a supply-chain cascade into LiteLLM, Mercor, and thousands of downstream targets, according to Oasis Security. The pattern shows that credential rotation without inventory, dependency mapping, and verification is not containment; it is deferred re-compromise.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “When Supply Chain Attacks Meet NHI Sprawl”.

Key questions

Q: What breaks when a leaked NHI credential is rotated but not fully revoked?

A: The original access path can remain usable if any downstream system still trusts the old secret, cached token, or surviving service account.

Q: Why do supply chain attacks become larger when NHI sprawl is unmanaged?

A: Because the initial compromise is only the entry point.

Q: How do security teams know whether NHI rotation is actually working?

A: Rotation is working only if teams can show that every exposed credential was found, replaced, and validated against downstream dependencies without disrupting production.

Practitioner guidance

  • Map every high-risk NHI credential to its consumers Build a live inventory that ties each privileged secret to its owner, downstream systems, and approval history so you can see what rotation will actually affect.
  • Verify rotation before closing the incident Treat revocation as incomplete until every credential in the affected blast radius has been invalidated and every dependent service has moved to a new secret.
  • Decommission stale machine credentials aggressively Remove credentials that no longer have a current business purpose, especially those created for temporary workflows, legacy integrations, or dormant CI paths.

Bottom line: The article frames the real risk as unmanaged NHI reach, not just the original supply chain entry point.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

NHI sprawl is the force multiplier that turns supply chain compromise into cascading breach scope. The article shows that the initial vector changed, but the outcome kept expanding because machine credentials already had reach across CI/CD, cloud, and secret management layers. That is why supply chain security and NHI governance cannot be separated in practice. Practitioners should treat every trusted automation path as part of the blast-radius model.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
  • NHIs outnumber human identities by 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who is accountable for closing exposed NHI access after a supply chain incident?

A: Accountability sits with the teams that own the credential, the downstream service that consumes it, and the incident responders coordinating revocation. In regulated environments, the broader governance function must ensure ownership, lifecycle records, and verification evidence exist before the incident is declared closed.

👉 Read our full editorial: Supply chain attacks expose the real blast radius of NHI sprawl


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.