# CHQ-ED-2026-018

- **Artifact ID:** CHQ-ED-2026-018
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-018
- **Machine-record SHA-256:** `a3632b4caa8815e4b3f43caf19aeca9c8a48e800dbde29df97df5376472cee4f`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-018",
  "associated_position": "CHQ-P-2026-015 v1.0",
  "relationship": "successor",
  "prior_docket_id": "CHQ-ED-2026-015",
  "issuance_date": "2026-05-04",
  "evidence_freeze_time": "2026-05-04T00:00:00Z",
  "total_exhibits": 4,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "OIDC trusted publishing — adopted across npm, PyPI, and other registries as a security improvement that replaces long-lived publishing tokens with short-lived workflow-bound tokens — was abused by compromising the workflow that earns the token, producing publication into the official scope through a path indistinguishable from legitimate releases at the registry level.",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ],
      "relevant_sections": "I. Factual Record — SAP CAP Compromise",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-04-30-01: Mini Shai-Hulud (TeamPCP) — Attacker compromised an SAP developer account with release workflow permissions, modified the GitHub Actions release workflow to extract the short-lived OIDC token at publication time, and used the token within its valid window to publish backdoored versions to the official @cap-js npm scope. The packages were signed. They came from the official scope. They passed every automated check."
    },
    {
      "claim_id": "C-02",
      "position_section": "Core Position",
      "claim_text": "A centralized AI gateway holding credentials for over one hundred upstream providers exercised effective publication authority over the credential pool, with compromise of the gateway’s authentication path producing extraction capability against credentials that would individually be governed by separate provider security models.",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ],
      "relevant_sections": "I. Factual Record — Targeted Data",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-05-01-01: LiteLLM CVE-2026-42208 — Pre-authentication SQL injection in the LiteLLM proxy enabled enumeration of three credential tables. The gateway operates as a publication authority surface — the credentials it holds determine which AI provider accounts authenticated requests reach."
    },
    {
      "claim_id": "C-03",
      "position_section": "Core Position",
      "claim_text": "A single git push command executed by an authenticated user with push access produced remote code execution on shared backend storage with cross-repository read access, demonstrating that the verification primitive — authentication — operates downstream of where authority is exercised.",
      "evidence_exhibits": [
        "CHQ-EX-2026-018"
      ],
      "relevant_sections": "I. Factual Record — Exploit Chain, Backend Scope",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-05-01-02: GitHub CVE-2026-3854 — User-supplied push option values injected into internal X-Stat service headers enabled three-stage exploitation: sandbox bypass, hook directory redirect, path traversal RCE. Authentication was the only gating control. Authentication material is now routinely harvested through supply chain operations against developer environments."
    },
    {
      "claim_id": "C-04",
      "position_section": "Core Position",
      "claim_text": "Two security vendors disclosed source code repository access within seven days through different actors and different vectors, exposing the internal logic of products customers rely on as security controls and creating attacker knowledge that persists beyond patch cycles.",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ],
      "relevant_sections": "I. Factual Record, II. Failure Pattern",
      "verification_type": "REINFORCING",
      "evidence_class": "REINFORCING",
      "source_text": "SN-2026-04-29-01 and SN-2026-05-03-01: Checkmarx and Trellix Source Code Exposure — Source code of security scanning tooling and endpoint detection products exposed to adversarial research. The asymmetry created by source code possession is not remediated by patches."
    },
    {
      "claim_id": "C-05",
      "position_section": "Evidence Pattern",
      "claim_text": "Across the documented signals, the verification primitives organizations rely on — package signing, OIDC token validation, authentication, integrity verification — operated at points downstream of where authority was being exercised. None could verify that the authority being exercised had not been compromised upstream of the verification boundary.",
      "evidence_exhibits": [
        "CHQ-EX-2026-016",
        "CHQ-EX-2026-017",
        "CHQ-EX-2026-018",
        "CHQ-EX-2026-020"
      ],
      "relevant_sections": "II. Failure Pattern",
      "verification_type": "PATTERN",
      "evidence_class": "PATTERN",
      "source_text": "Pattern across SN-2026-04-30-01, SN-2026-05-01-01, SN-2026-05-01-02, SN-2026-04-29-01, SN-2026-05-03-01. The execution pipeline accepted the verification result as authority. The verification result certified continuity of authorization, not correctness of authorization. The gap between the two is the structural attack surface."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-04-30-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ]
    },
    {
      "signal_id": "SN-2026-05-01-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ]
    },
    {
      "signal_id": "SN-2026-05-01-02",
      "signal_type": "SECURITY_RESEARCH",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-018"
      ]
    },
    {
      "signal_id": "SN-2026-04-29-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ]
    },
    {
      "signal_id": "SN-2026-05-03-01",
      "signal_type": "VENDOR_DISCLOSURE",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-020"
      ]
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-016",
      "title": "LiteLLM CVE-2026-42208: AI Gateway Pre-Authentication Credential Extraction",
      "temporal_tag": "OPERATIONAL (APRIL 24–26, 2026)"
    },
    {
      "id": "CHQ-EX-2026-017",
      "title": "Mini Shai-Hulud (TeamPCP): SAP CAP and PyTorch Lightning Cross-Registry Compromise",
      "temporal_tag": "OPERATIONAL (APRIL 29–30, 2026)"
    },
    {
      "id": "CHQ-EX-2026-018",
      "title": "GitHub CVE-2026-3854: Remote Code Execution via Single Git Push Command",
      "temporal_tag": "OPERATIONAL (MARCH 4 – APRIL 28, 2026)"
    },
    {
      "id": "CHQ-EX-2026-020",
      "title": "Security Vendor Source Code Exposure Class: Checkmarx and Trellix",
      "temporal_tag": "OPERATIONAL (APRIL 26 – MAY 2, 2026)"
    }
  ],
  "notice": [
    "This docket is a successor to CHQ-ED-2026-015 issued March 25, 2026. The original docket records the March 2026 evidence base from the Trivy-to-Ecosystem cascade. This docket appends the April–May 2026 evidence base. Both dockets together constitute the cumulative evidence record for CHQ-P-2026-015 v1.0."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-015 v1.0, succeeding CHQ-ED-2026-015 with the April–May 2026 evidence record.",
    "All primary signals classified CONFIRMED based on independent verification across multiple analytical teams or official vendor disclosure. The four exhibit entries each demonstrate the same structural condition through distinct mechanisms: workflow trust abuse (Mini Shai-Hulud), credential aggregation compromise (LiteLLM), authentication-as-sole-control failure (GitHub push RCE), and verification-of-detection-logic compromise (security vendor source code). Failure mode independence is high.",
    "CCD record — five layers decomposed (workflow authority, credential aggregation, authentication boundary, verification primitive scope, detection logic exposure), all CONFIRMED. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH.",
    "Primary signals compiled from CHQ Classification Log. All signals passed TSEM evaluation. Source independence assessed per CCD enforcement protocol. Failure mode independence assessed per convergence scaling constraint.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-018 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-015 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
