5. Insufficient Credential Hygiene
Coming in at the bottom of our ranking is a risk that’s as common as it is preventable: poor credential management. This is the digital equivalent of leaving keys under the doormat. Developers, often in a rush, might hardcode secrets like API keys or passwords
directly into configuration files or source code. These then get committed to a code repository, where they can be discovered by anyone with access. Attackers actively scan for these exposed secrets to gain an initial foothold. While tools exist to detect these leaks, the fast pace of development means they frequently slip through, providing an easy entry point for bad actors.
4. Inadequate Access Management
If the build pipeline is a kingdom, who holds the keys? Too often, the answer is 'too many people.' Inadequate Identity and Access Management (IAM) means that human and machine identities have excessive privileges across the multiple systems that make up a CI/CD pipeline—from source control to cloud deployment targets. Stale accounts from former employees or overly permissive service accounts create a massive attack surface. The infamous Codecov breach, for instance, exploited a permissive CI token to steal secrets from thousands of customer pipelines, proving that a single weak link can compromise the entire chain.
3. Improper Artifact Integrity Validation
Imagine a factory where anyone could swap a real product with a counterfeit one just before it gets boxed up. That’s the threat of improper artifact validation. A build artifact—the compiled code, container image, or package—is the final product of your pipeline. Without a way to cryptographically sign and verify these artifacts at each stage, an attacker who gains access can tamper with them. They could replace a legitimate container image with one containing a backdoor, and without integrity checks, this malicious version gets shipped directly to production and to your customers. Major incidents like the PHP backdoor attack highlight how devastating this can be.
2. Dependency Chain Abuse
Modern software is built on a mountain of open-source dependencies, and attackers have learned to poison the well. Dependency chain abuse involves compromising a third-party library that your application relies on. By injecting malicious code into a popular package, attackers can execute a supply chain attack that affects every single project that uses it. This technique, which has seen a massive rise in recent years, bypasses your direct security controls by making the attack look like a normal software update. Attacks like the one that compromised SolarWinds's build system show the scale of damage possible, affecting up to 18,000 organizations through a single trusted update.
1. Poisoned Pipeline Execution (PPE)
At the top of our list is the most direct and dangerous threat: Poisoned Pipeline Execution (PPE). This is where an attacker doesn't just compromise a component in the pipeline; they compromise the pipeline's instructions itself. By manipulating the build configuration, an attacker can inject malicious commands that run with the full authority of the build process. This gives them the 'master key' to the whole kingdom—access to all secrets, source code, and deployment systems connected to the pipeline. It's the ultimate shortcut, allowing an adversary to bypass other defenses and use your own trusted automation against you to steal data or deploy malware.













