Why Are OSS Attackers Always After CI/CD Credentials?
Sonatype reports that 53% of malicious packages analyzed in 2025 targeted developer environments during installation to steal CI/CD credentials. These tokens grant access to source code, build systems, and cloud infrastructure. The article explains how preinstall scripts on workstations and runners can capture secrets before traditional application security scans occur, highlighting the supply chain risk.
