Sample Detection Events
S3 and WebHook Integrations
Threat-Intelligence
{
"id": "78540701-3106-4eaa-9408-8902e87bd27d",
"event_id": "78540701-3106-4eaa-9408-8902e87bd27d",
"type": "Threat-Intelligence",
"incident_start_time": "2025-09-15T22:41:00Z",
"title": "Tinycolor NPM Supply Chain Attack - 40+ Packages Compromised with Credential Harvester",
"details": "# Tinycolor NPM Supply Chain Attack - 40+ Packages Compromised\n\n## Executive Summary\n\nA malicious update to @ctrl/tinycolor (2.2M weekly downloads) was detected on npm as part of a broader supply-chain attack that impacted more than ...",
"ecosystem": "npm",
"description": "A malicious update to @ctrl/tinycolor (2.2M weekly downloads) was detected on npm as part of a broader supply-chain attack that impacted more than 40 packages spanning...",
"severity": "HIGH",
"is_active": "true",
"incident_url": "https://app.stepsecurity.io/github/your-org/threat-center/incidents/78540701-3106-4eaa-9408-8902e87bd27d"
}Action-Uses-Commit-From-Non-Default-Branch
Action-Uses-Imposter-Commit
Domain-Blocked
HTTPS-Outbound-Network-Call
New-Outbound-Network-Call
Privileged-Container
Reverse-Shell
Runner-Worker-Memory-Read
Secret-In-Build-Log
Secret-In-Artifact
Source-Code-Overwritten
Actions-Policy-Blocked
Runs-On-Policy-Blocked
Secrets-Policy-Blocked
Compromised-Actions-Policy-Blocked
PyPI Package Cooldown Check Failure
PyPI Package Compromised Updates Check Failure
Lockdown Detection Event
NPM Package Cooldown Check Failure
NPM Package Compromised Updates Check Failure
PWN Request Check Failure
Script Injection Check Failure
Baseline Check Failure (Harden-Runner)
Secure Registry Audit Log Events
S3 Batch Format
Webhook Payload
Insights Response
Last updated
Was this helpful?