
Team PCP, 2,186개 조직에서 secret 78,330개 탈취
CloudSEK의 Team PCP dataset은 손상된 open-source component가 신뢰받는 pipeline에서 실행된 뒤 5일 동안 2,186개 조직에서 secret 78,330개가 유출됐다고 기록합니다. GitLab, Azure DevOps, GitHub, host, mail system 전반에서 JWT 999개 조직, private key 480개, AWS key 320개, OpenAI key 157개가 포함됐습니다. 공격자는 탈취한 repository·publishing credential로 다음 supply-chain compromise를 만드는 flywheel을 구성합니다. StepSecurity는 즉시 rotation한 뒤 downstream access audit, immutable dependency reference, runner runtime monitoring, deny-by-default egress를 권고합니다. Vendor 분석이라는 한계는 있지만 공개된 규모와 credential class는 pipeline boundary를 무시할 수 없게 합니다.

