The recent discovery of malicious packages in the PyPI and npm registries, designed to steal developer credentials and environment variables from CI/CD systems, highlights a growing threat in the software supply chain. These types of attacks, which specifically target payment SDKs like PaySafe or Skrill, exploit the trust that teams place in external dependencies. For organizations developing custom applications, integrating third-party libraries without rigorous security analysis can open doors to serious compromises in continuous integration and deployment pipelines.
From a technical perspective, these malicious packages not only extract sensitive data but can also inject persistent code that affects cloud environments. Therefore, it is essential for companies to adopt proactive cybersecurity strategies, combining automated dependency scanning with access control policies. At Q2BSTUDIO, we understand that security goes beyond development; that is why we offer cybersecurity and pentesting services that evaluate both proprietary code and external libraries, protecting your organization's critical assets.
Additionally, the threat extends to cloud infrastructures: attackers target environment variables containing access keys to AWS and Azure cloud services. Inadequate management of these secrets can lead to data leaks or resource hijacking. To mitigate this, we recommend implementing artificial intelligence solutions that monitor anomalous patterns in pipelines, or even deploying AI agents that automate real-time vulnerability detection. In parallel, business intelligence services tools such as Power BI can help visualize the security posture throughout the software lifecycle, integrating data from scans and access logs.
In an environment where custom software is increasingly complex and supply chains diversify, the combination of AI for businesses with robust security practices becomes indispensable. At Q2BSTUDIO, we help organizations fortify their development processes, integrating both automation and human oversight, so that no malicious package compromises the integrity of their CI/CD systems.

.jpg)


