Malware in PyPI and npm payment SDKs compromises CI/CD

Discover how 17 malicious packages in PyPI and npm steal credentials and CI/CD environment variables. Protect your software supply chain.

miércoles, 8 de julio de 2026 • 1 min read • Q2BSTUDIO Team

Malware campaign targets CI/CD environments

The recent discovery of malicious packages in the PyPI and npm registries, designed to steal developer credentials and environment variables from CI/CD systems, highlights a growing threat in the software supply chain. These types of attacks, which specifically target payment SDKs like PaySafe or Skrill, exploit the trust that teams place in external dependencies. For organizations developing custom applications, integrating third-party libraries without rigorous security analysis can open doors to serious compromises in continuous integration and deployment pipelines.

From a technical perspective, these malicious packages not only extract sensitive data but can also inject persistent code that affects cloud environments. Therefore, it is essential for companies to adopt proactive cybersecurity strategies, combining automated dependency scanning with access control policies. At Q2BSTUDIO, we understand that security goes beyond development; that is why we offer cybersecurity and pentesting services that evaluate both proprietary code and external libraries, protecting your organization's critical assets.

Additionally, the threat extends to cloud infrastructures: attackers target environment variables containing access keys to AWS and Azure cloud services. Inadequate management of these secrets can lead to data leaks or resource hijacking. To mitigate this, we recommend implementing artificial intelligence solutions that monitor anomalous patterns in pipelines, or even deploying AI agents that automate real-time vulnerability detection. In parallel, business intelligence services tools such as Power BI can help visualize the security posture throughout the software lifecycle, integrating data from scans and access logs.

In an environment where custom software is increasingly complex and supply chains diversify, the combination of AI for businesses with robust security practices becomes indispensable. At Q2BSTUDIO, we help organizations fortify their development processes, integrating both automation and human oversight, so that no malicious package compromises the integrity of their CI/CD systems.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.