Join our Newsletter — 33% off our NHI Course

Cloud supply chain attacks: what identity teams are missing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Unosecur reports that poisoned packages and compromised build workflows are being used to steal developer tokens, SSH keys, API keys and cloud credentials, then pivot into repositories, CI/CD pipelines and cloud control planes. The assumption that attackers must break in is collapsing as identity becomes the practical perimeter.

Editorial analysis by NHI Mgmt Group, based on content published by Unosecur: “From Package Poisoning to Cloud Admin — Identity-Driven Analysis”.

Key questions

Q: What breaks when poisoned packages harvest developer credentials?

A: The break is not just code execution.

Q: Why do CI/CD identities increase cloud takeover risk when they are overprivileged?

A: Because deployment identities are already trusted to move code into production and often sit close to sensitive cloud permissions.

Q: How can security teams tell if identity abuse is happening in the pipeline?

A: Look for unexpected token use, unusual OIDC role assumptions, service accounts performing new actions and IAM changes that do not match the release process.

Practitioner guidance

  • Reduce secret density on developer endpoints Remove long-lived GitHub tokens, SSH keys, API keys and cloud credentials from standard developer workstations wherever possible, and keep local secret storage tightly scoped to active work only.
  • Tighten OIDC trust between pipelines and cloud roles Review which workflows can assume which cloud IAM roles, then narrow claims, audiences and role bindings so one compromised pipeline identity cannot fan out across environments.
  • Separate deployment access from identity-management rights Prevent CI/CD roles from creating or modifying administrator identities, policy attachments or privilege-bearing roles unless that function is explicitly required and justified.

Bottom line: Cloud supply chain attacks increasingly succeed by stealing and reusing trusted identities rather than by exploiting infrastructure weaknesses.

What's in the full article

Unosecur's full blog covers the operational detail this post intentionally leaves for the source:

  • Walkthrough of the Nx attack chain from workflow compromise to credential theft
  • Examples of identity telemetry that can expose stolen GitHub token and OIDC activity
  • Discussion of Unosecur's detection logic for privileged identity abuse across cloud and developer environments
  • Implementation-focused examples for monitoring service accounts, API tokens and CI/CD roles

👉 Read Unosecur's analysis of identity risk in cloud supply chain attacks →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Identity is now the primary cloud perimeter, not the network edge. The article is right to frame the Nx compromise as an identity event rather than a malware event. When a package can collect tokens, keys and cloud credentials, the attacker inherits legitimate access paths instead of forcing entry. For practitioners, that means the security boundary is defined by who and what can authenticate, not by where the workload sits.

A question worth separating out:

Q: How should organisations reduce the blast radius of build and deploy identities?

A: Limit the permissions of package managers, signing services, and deployment automation to the smallest set needed for their task. Separate fetch, sign, and promote functions, rotate required secrets, and prefer workload identity where feasible. That prevents one compromised automation account from controlling the entire release chain.

👉 Read our full editorial: Identity is the real perimeter in cloud supply chain attacks


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.