News

Developer infra becomes primary target for supply chain attacks

The shift from perimeter defense to supply chain compromise has moved from theoretical concern to operational reality. Over the past three months, attackers have systematically targeted the tools developers use to build software, exploiting a fundamental architectural weakness: organizations trust code repositories, package managers, and collaboration platforms because they must. What has changed is not the existence of supply chain risk but the industrialization of attacks against it. Threat actors now operate with the automation, persistence, and precision once reserved for nation-state campaigns, and they are succeeding at scale.

The dismantling of the Glassworm botnet by CrowdStrike, Google, and Shadowserver in late May reveals how sophisticated these operations have become. The attackers maintained persistence across four distinct communication channels—Solana blockchain, BitTorrent, Google Calendar, and commercial virtual private servers—ensuring that disrupting one path would not collapse the operation. Glassworm infected more than 300 GitHub repositories and seeded malware into VSCode extensions, npm packages, and Python libraries. This was not opportunistic compromise. The operation automated propagation through trusted developer workflows, moving laterally through continuous integration and delivery pipelines to reach downstream victims without triggering traditional security controls.

Days after the Glassworm takedown, CISA issued an alert on supply chain compromises affecting Nx Console and multiple GitHub repositories, evidence that the threat persists despite enforcement actions. Separately, researchers disclosed an unpatched zero-day vulnerability in Gogs, a self-hosted Git service used by organizations seeking alternatives to GitHub Enterprise or GitLab. The flaw allows any authenticated user to execute arbitrary code remotely through a malicious pull request that injects arguments into the server’s rebase process. Gogs ships with open registration enabled by default, meaning an attacker needs no insider access—only the ability to create an account. More than 2,400 Gogs servers remain exposed online, most in Asia and Europe, and maintainers have not responded to disclosure since acknowledging the report in March. This marks the second Gogs remote code execution vulnerability exploited in the wild within six months.

Organizations running developer infrastructure on Internet-facing servers face compounding exposure. That same week, CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog, including a critical flaw in FortiClient EMS already under active exploitation. The pattern is consistent: attackers target management and collaboration tools that aggregate access to multiple systems, then move laterally. A compromised Git server provides access to every repository it hosts. A breached package manager delivers malicious code to every developer who pulls dependencies. The attack surface isn’t measured by the number of servers exposed but by the degree of trust each one commands within the development pipeline.

Software development shops, DevOps teams, and organizations with decentralized engineering cultures face the highest risk. These environments prioritize speed and collaboration, often enabling open registration, relaxed repository creation limits, and broad access permissions to avoid friction. The same configurations that make developers productive also make attackers effective. Smaller organizations running self-hosted tools like Gogs lack the resources to harden default configurations or respond quickly to disclosed vulnerabilities, leaving them exposed for months. Larger enterprises have a different problem: visibility into the full dependency chain is often incomplete, and malicious packages can propagate undetected through automated build processes.

Security investment must now prioritize the integrity of the build environment itself. Monitoring developer tooling for unauthorized access, enforcing strict repository permissions, disabling default open registration on self-hosted services, and implementing software bill of materials tracking are baseline controls, not optional enhancements. Glassworm and Gogs demonstrate that attackers no longer need to breach the target directly. They breach the tools the target trusts, and the software does the rest.

Contact Us

InfoTransec Inc.

Telephone:
+1 855-INFOSEC (463-6732)

Hours:
9am – 5pm   Weekdays

Address:
The Atrium @ MIP
McMaster Innovation Park
Suite 416A-8
175 Longwood Road South,
Hamilton, ON, L8P 0A1

Nationwide Service

Primarily based out of Hamilton, InfoTransec also services the following areas within Southern Ontario and the GTA.

 Brantford
 Burlington
 Cambridge
 Hamilton
 Kitchener
 London
 Milton
 Mississauga
 Oakville
 St. Catharine’s
 Toronto
 Waterloo

Nationwide service is also available.

Our Tweets
NVD Vulnerabilities
Nationwide Service

Primarily based out of Hamilton, InfoTransec also services the following areas within Southern Ontario and the GTA.

 Brantford
 Burlington
 Cambridge
 Hamilton
 Kitchener
 London
 Milton
 Mississauga
 Oakville
 St. Catharine’s
 Toronto
 Waterloo

Nationwide service is also available.

Our Tweets
NVD Vulnerabilities

© InfoTransec – 2019 – All Rights Reserved | Privacy Policy

Icons made by Freepik from www.flaticon.com is licensed by CC 3.0 BY