Sample Detection Events
S3 and WebHook Integrations
Threat-Intelligence
{
"id": "78540701-3106-4eaa-9408-8902e87bd27d",
"event_id": "78540701-3106-4eaa-9408-8902e87bd27d",
"type": "Threat-Intelligence",
"incident_start_time": "2025-09-15T22:41:00Z",
"title": "Tinycolor NPM Supply Chain Attack - 40+ Packages Compromised with Credential Harvester",
"details": "# Tinycolor NPM Supply Chain Attack - 40+ Packages Compromised\n\n## Executive Summary\n\nA malicious update to @ctrl/tinycolor (2.2M weekly downloads) was detected on npm as part of a broader supply-chain attack that impacted more than ...",
"ecosystem": "npm",
"description": "A malicious update to @ctrl/tinycolor (2.2M weekly downloads) was detected on npm as part of a broader supply-chain attack that impacted more than 40 packages spanning...",
"severity": "HIGH",
"is_active": "true",
"incident_url": "https://app.stepsecurity.io/github/your-org/threat-center/incidents/78540701-3106-4eaa-9408-8902e87bd27d"
}Action-Uses-Commit-From-Non-Default-Branch
Action-Uses-Imposter-Commit
Domain-Blocked
HTTPS-Outbound-Network-Call
New-Outbound-Network-Call
Privileged-Container
Reverse-Shell
Runner-Worker-Memory-Read
Secret-In-Build-Log
Secret-In-Artifact
Source-Code-Overwritten
Actions-Policy-Blocked
Runs-On-Policy-Blocked
Secrets-Policy-Blocked
Compromised-Actions-Policy-Blocked
Lockdown Detection Event
Last updated
Was this helpful?