cloud.google.com 24 Sept 2026, 14:00 UTC

Mandiant Warns Attackers Are Targeting Developer Tools and CI/CD Pipelines

Mandiant Warns Attackers Are Targeting Developer Tools and CI/CD Pipelines
CyberSIXT Evidence Panel Source marked as original reporting

MANDIANT has published guidance for hardening software development lifecycles after recent supply-chain campaigns targeted trusted security scanners, utility libraries and AI developer tools. The company says attackers are also targeting developer workstations and IDEs through social engineering, malicious extensions and typosquatted dependencies to steal personal access tokens, SSH keys, API tokens and session credentials.

More advanced techniques include GitHub Actions cache poisoning, OpenID Connect (OIDC) token extraction and changing mutable action tags so compromised packages retain legitimate cryptographic provenance. The guidance is presented as a defensive blueprint rather than a report of a single incident, and does not identify specific victims or CVEs.

Mandiant recommends a layered approach covering endpoints, repositories, artefact management, CI/CD and deployment. Measures include approved and version-pinned IDEs and extensions, pre-commit secret scanning, phishing-resistant MFA, branch protection and short-lived credentials.

Organisations are advised to use exact dependency versions, cryptographically verified lockfiles, seven-day release-age cooldowns for newly published public packages, internal proxies and quarantines, continuous scanning, signed SBOMs and immutable SHA-256 or commit-hash references instead of mutable tags. For pipelines, it recommends ephemeral runners, restricted network access, manual approval for untrusted pull requests, branch-isolated caches, OIDC-based short-lived identities and least-privilege permissions.

Production controls should verify artefact signatures, enforce hardened workloads and continuously monitor cloud configuration, network activity and audit logs.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline