# CHQ-ED-2026-016

- **Artifact ID:** CHQ-ED-2026-016
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-016
- **Machine-record SHA-256:** `4eb3acab5e0c3f4527e5168d058ea4c7d559ae2e84f7a02437e4b1e5e834eaf8`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-016",
  "associated_position": "CHQ-P-2026-013 v1.0",
  "relationship": "reinforcement",
  "issuance_date": "2026-05-04",
  "evidence_freeze_time": "2026-05-04T00:00:00Z",
  "total_exhibits": 3,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "Credentials harvested from one developer’s compromised environment in a supply chain operation produced authority to publish into ecosystems unrelated to the initial access point, with no architectural mechanism present to contain the spread within the registry where the credentials were originally issued.",
      "evidence_exhibits": [
        "CHQ-EX-2026-014"
      ],
      "relevant_sections": "I. Factual Record — Cascade, Mechanism",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-03-19-01: Trivy GitHub Actions Compromise — Stolen npm tokens, GitHub Actions credentials, and PyPI publish tokens harvested from compromised CI/CD pipelines were used in subsequent operations to publish to npm, PyPI, Open VSX, and Docker Hub. The credential was portable across registries because the developer identity was. No registry independently verified that the token in use was held by the maintainer who originally received it."
    },
    {
      "claim_id": "C-02",
      "position_section": "Core Position",
      "claim_text": "The TeamPCP credential cascade demonstrated that a single developer’s compromised environment produced cross-registry attack capability spanning at least five distinct package distribution ecosystems within a six-day operational window.",
      "evidence_exhibits": [
        "CHQ-EX-2026-014"
      ],
      "relevant_sections": "I. Factual Record — Cascade",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-03-25-01: Trivy-to-Ecosystem Credential Cascade — Compromise of one developer’s CI/CD pipeline yielded credentials sufficient to compromise unrelated GitHub Actions in third-party repositories, npm packages from a different vendor, Open VSX extensions, and PyPI packages used in distinct enterprise contexts."
    },
    {
      "claim_id": "C-03",
      "position_section": "Core Position",
      "claim_text": "Mini Shai-Hulud demonstrated cross-registry expansion as a deliberate operational pattern, with the same actor publishing malicious payloads simultaneously to npm and PyPI through different mechanisms in each registry, harvesting credentials for further cross-registry propagation.",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ],
      "relevant_sections": "I. Factual Record — SAP CAP Compromise, PyTorch Lightning Compromise",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-04-30-01: Mini Shai-Hulud (TeamPCP) — Publication to npm via OIDC trusted publishing abuse and publication to PyPI via direct token compromise occurred in the same forty-eight hour window using shared payload infrastructure."
    },
    {
      "claim_id": "C-04",
      "position_section": "Evidence Pattern",
      "claim_text": "Across the documented signals, developer identity served as the primary trust path between registries that have no shared authorization model. Each registry treated possession of a valid credential as proof of legitimate publishing intent.",
      "evidence_exhibits": [
        "CHQ-EX-2026-014",
        "CHQ-EX-2026-015",
        "CHQ-EX-2026-017"
      ],
      "relevant_sections": "II. Failure Pattern",
      "verification_type": "PATTERN",
      "evidence_class": "PATTERN",
      "source_text": "Pattern across SN-2026-03-19-01, SN-2026-03-25-01, SN-2026-03-31-01, SN-2026-04-30-01. The portable developer identity is the credential surface attackers operate against. Registry-level isolation does not contain compromise of the developer environment because the developer identity is what each registry trusts."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-03-19-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-014"
      ]
    },
    {
      "signal_id": "SN-2026-03-25-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-014"
      ]
    },
    {
      "signal_id": "SN-2026-03-31-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-015"
      ]
    },
    {
      "signal_id": "SN-2026-04-30-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ]
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-014",
      "title": "TeamPCP: Institutional Infrastructure Compromise via CI/CD Supply Chain",
      "temporal_tag": "CONTEMPORANEOUS (FEBRUARY TO APRIL 2026)"
    },
    {
      "id": "CHQ-EX-2026-015",
      "title": "UNC1069/Axios: North Korean Supply Chain Compromise via Maintainer Account",
      "temporal_tag": "OPERATIONAL (MARCH 31, 2026)"
    },
    {
      "id": "CHQ-EX-2026-017",
      "title": "Mini Shai-Hulud (TeamPCP): SAP CAP and PyTorch Lightning Cross-Registry Compromise",
      "temporal_tag": "OPERATIONAL (APRIL 29–30, 2026)"
    }
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-013 v1.0.",
    "Primary signals: SN-2026-03-19-01, SN-2026-03-25-01, and SN-2026-04-30-01 are all classified CONFIRMED based on independent verification across multiple analytical teams and official vendor confirmation. SN-2026-03-31-01 (Axios maintainer compromise) is REINFORCING — distinct actor (UNC1069), distinct mechanism (account takeover), but reinforces the same structural condition that developer identity serves as a transitive trust path across registry boundaries.",
    "CCD record — three layers decomposed (credential harvest, cross-registry propagation, identity-as-trust-path), all CONFIRMED. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH.",
    "Primary signals compiled from CHQ Classification Log. All signals passed TSEM evaluation. Source independence assessed per CCD enforcement protocol. Failure mode independence assessed per convergence scaling constraint.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-016 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-013 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
