Skip to content
All posts

INDUSTRY

Your tool stack is your attack surface — July proved it, one package at a time

6 min read

In four weeks the work toolchain was hit through a poisoned npm package hunting AI-assistant configs, a PNG that walked past AI code reviewers, a release pipeline that shipped malware with valid provenance, and a worm that swallowed 440 packages in an hour. Third-party breaches just doubled to 48%. Shrinking the stack is no longer tidiness — it is security posture.

Over four weeks this summer, the toolchain that knowledge work runs on was breached through four different doors. On 11 July, attackers used a stolen publishing credential to push five poisoned versions of jscrambler, an npm package with some fifteen thousand weekly downloads — its infostealer explicitly enumerates Claude Desktop configuration, Cursor’s MCP settings and other AI-assistant credential stores (Socket flagged the first bad version within six minutes). The same day, researchers disclosed Ghostcommit: prompt-injection instructions hidden inside a PNG committed to a pull request, which a vision-capable coding agent later reads and obeys — walking secrets past both human and AI review. Three days later the AsyncAPI npm packages, with millions of weekly downloads, shipped malicious releases through a hijacked CI pipeline, carrying valid build provenance. And on 4 August, a wave of the Shai-Hulud worm swallowed more than 440 packages — including dependencies with hundreds of millions of weekly downloads — in roughly an hour. Sonatype counted 454,648 new malicious open-source packages in 2025, up 75% in a year. This is not a string of coincidences; it is a strategy.

Four weeks, four doors · July–August 2026
11 Juljscrambler (npm)stolen publishing key; infostealer harvesting Claude Desktop / Cursor MCP configs
11 JulGhostcommitinstructions hidden in a PR’s PNG; walked past AI code reviewers (research PoC)
14 JulAsyncAPI (npm)CI/CD pipeline hijacked; malicious releases shipped with valid provenance
4 AugShai-Hulud waveself-replicating worm; 440+ packages in about an hour, millions of weekly downloads
Four different doors — a package, an image, a pipeline, a worm — one target: the work and dev toolchain itself. Ghostcommit is a research proof-of-concept; the rest were live.
Four verified incidents, four different mechanisms — the common target is the toolchain itself.

The pattern: attackers moved to where the credentials live

Look at what the jscrambler payload actually hunts: not just browser sessions and cloud keys, but the configuration files of AI coding assistants — because that is where API keys and MCP server credentials now sit. Ghostcommit’s deeper finding points the same way. Testing the same underlying models across different coding tools, the researchers found the outcome depended on the harness, not the model: the same model leaked secrets in one tool and refused in another (one agent, Claude Code, refused across every model tested). And the reason the attack class works at all is human: in the researchers’ own survey of 6,480 pull requests across the 300 most active public GitHub repositories, 73% of merged PRs reached the default branch with no substantive review by anyone — human or bot. The toolchain is not just software; it is the place where trust is assumed rather than checked.

Sprawl is the surface

Zoom out and the toolchain problem becomes a stack problem. Verizon’s 2026 data-breach report found a third party involved in 48% of breaches — up from 30% a year earlier. And the stack those third parties make up keeps growing: Zylo’s 2026 index puts the average company at 305 SaaS applications, with business units controlling 81% of the spend and IT directly managing 15%; BetterCloud’s July 2026 survey found only 56% of apps carry IT approval; Verizon measured employee use of unapproved AI tools tripling from 15% to 45% in a year. Every one of those apps is a vendor relationship, an OAuth grant and a data path — and one compromised integration is enough. That is not hypothetical: in August 2025, attackers used stolen OAuth tokens from a single AI chat widget, Salesloft’s Drift, to pull data out of the Salesforce tenants of more than 700 organisations.

The agent layer makes every tool heavier

What changed in 2026 is that the average app now has an agent inside it. Okta’s Businesses at Work 2026 found 91% of organisations already using AI agents — and only 10% with a well-developed strategy for managing them; just 32% secure agents with the rigour they apply to human employees. In SailPoint’s survey, 80% of organisations said their agents had already taken unintended actions, including 39% that accessed systems they should not have. Palo Alto Networks now counts 109 machine identities per human. And assistants inside suites have repeatedly been shown able to leak the suite: prompt injection turned Slack’s AI against private channels in 2024; EchoLeak made Microsoft 365 Copilot exfiltrate files zero-click in 2025; SearchLeak did it again this June with a single click; ServiceNow’s Now Assist agents could be talked into recruiting each other last November. All of these were responsibly disclosed and patched, with no confirmed exploitation in the wild — the Drift breach is the one with real victims. But the direction is unambiguous: every extra tool now ships with an extra actor inside it.

Everyone wants consolidation. Sprawl is winning.

None of this is news to buyers. As far back as 2022, Gartner found 75% of organisations pursuing security-vendor consolidation. Productiv’s telemetry showed average portfolios falling from 374 to 342 apps as teams consolidated into suites, and Zylo’s 2026 index recorded the first flat portfolio year after years of growth. But the same reports carry the honest twist: BetterCloud measured the pace of consolidation actually slowing — from 14% to about 5% a year — while AI re-inflates the stack, with organisations now running 27 AI-powered apps on average and mid-market portfolios jumping from 116 to 164 apps in a single year. The lesson is not that consolidation failed. It is that consolidation loses whenever each new capability arrives as yet another tool — and wins when the capability arrives inside a workspace you already govern.

The surface math · many doors vs one door

The scattered stack

vendorOAuth grantAI agent
third party involved in 48% of breaches — Verizon DBIR 2026only 56% of apps carry IT approval — BetterCloud 2026

One workspace

projects · wiki · chat · dashboards · agents
SSO / SAML MFA RBAC audit log self-host
one vendor · one identity · one trail
Consolidation does not make the surface zero — one workspace is a bigger single prize. The trade is many perimeters you cannot control for one you can.
Eight tools, each dragging a vendor, an OAuth grant and an agent — against one workspace behind one identity, one policy and one audit trail.

Where SetGet stands

SetGet is our answer to exactly this math. It is the AI-native work OS that folds the duct-taped stack into one workspace: projects, a wiki, realtime chat, dashboards with 27+ widgets and AI agents, viewed as board, list, spreadsheet, Gantt or calendar. Migration paths exist precisely because consolidation has to be practical: bring your work in from Jira, Linear, Asana, ClickUp or Monday, and keep the integrations that earn their place — GitHub, GitLab, Slack, Sentry — through one REST API with OAuth and webhooks. The security posture is the point: one SSO with SAML and MFA, role-based access, an audit log on everything, and the option to self-host or run fully isolated, so the workspace — and everything in it — sits inside a perimeter you control. And the agent inside is not a third-party bolt-on with its own data path: SetGet’s AI runs on our own model families through the Qevron gateway, the same sovereign stack as the rest of the platform.

We will not pretend consolidation makes the surface zero. One workspace is a bigger single prize, and an agent inside it needs the same discipline as an employee — which is exactly why the workspace ships with one identity layer, one permission model and one audit trail instead of forty. The trade we are offering is not risklessness; it is many perimeters you cannot control, exchanged for one you can.

SetGet: projects, wiki, chat, dashboards and agents in one governed workspace.
Every tab is a vendor. Every vendor is a perimeter you do not control. Consolidation means having fewer of those — and owning the one that is left.

For teams under Türkiye’s KVKK, the stack math has a legal name: every SaaS tool that touches personal data is a veri işleyen — a processor you must vet, contract with and answer for, because the Article 12 security obligation does not stop at your own walls. Forty tools is forty processor relationships, most of them adopted without IT, let alone legal. A consolidated, self-hosted workspace shortens that chain to something you can actually audit — and when it runs inside your own perimeter, the question “where does our work data live?” has a one-word answer. SetGet, from Arpanet Bilişim A.Ş., was engineered for the KVKK from its first line. You can start free — and for deployment and scale, contact us and we will scope it with you.