# CHQ-ED-2026-020

- **Artifact ID:** CHQ-ED-2026-020
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-020
- **Machine-record SHA-256:** `5ff17a3c1aa582f1c82b52c4aa8293087bde57571b367b74898fe1ac15c57c7a`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-020",
  "associated_position": "CHQ-P-2026-016 V1.0",
  "relationship": "original",
  "issuance_date": "2026-05-04",
  "evidence_freeze_time": "2026-05-04T00:00:00Z",
  "total_exhibits": 6,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "GitHub Actions runners inherit execution authority from tag references without verifying that the code at the referenced tag has the right to exercise that authority — the tag reference is the provenance signal, and the provenance chain was intact while the code it pointed to had been replaced.",
      "evidence_exhibits": [
        "CHQ-EX-2026-009"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 1",
      "verification_type": "PRIMARY",
      "evidence_class": "E1",
      "source_text": "SN-2026-03-19-01: Trivy GitHub Actions compromise. 75 of 76 version tags force-pushed to malicious payload. Runners granted the compromised action full access to pipeline secrets as a design feature. No verification occurred between the tag reference and the code that executed. Source: Wiz / Aqua Security."
    },
    {
      "claim_id": "C-02",
      "position_section": "Core Position",
      "claim_text": "npm's postinstall hook mechanism executes with full access to the developer environment as a design feature — the registry accepted publication because the token was valid, and token validity verified continuity of the credential chain, not that the publishing entity was the legitimate maintainer.",
      "evidence_exhibits": [
        "CHQ-EX-2026-009"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 2",
      "verification_type": "PRIMARY",
      "evidence_class": "E1",
      "source_text": "SN-2026-03-20-01: GlassWorm Wave 3 / CanisterWorm. Stolen npm tokens from Trivy pipeline compromise used to publish 47+ malicious npm packages. CanisterWorm deployed as self-propagating credential harvester. At no point did any system verify that the publishing entity was the legitimate maintainer. Source: Aikido / Socket / Endor Labs."
    },
    {
      "claim_id": "C-03",
      "position_section": "Core Position",
      "claim_text": "OIDC trusted publishing produced signed packages from the official SAP scope because the attacker modified the workflow that earned the token — every verification primitive confirmed continuity (signed, scoped, attested) while none confirmed correctness.",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 3",
      "verification_type": "PRIMARY",
      "evidence_class": "E2",
      "source_text": "SN-2026-04-30-01: Mini Shai-Hulud. TeamPCP modified the GitHub Actions workflow in the SAP CAP repository to earn an OIDC token scoped to the legitimate @sap npm scope. PyTorch Lightning repository similarly compromised. Signed packages published from official scopes. Source: ReversingLabs / SAP Security Advisory."
    },
    {
      "claim_id": "C-04",
      "position_section": "Core Position",
      "claim_text": "Compromise of a maintainer's npm credentials produced publications that passed all registry-level verification — the credential was the provenance anchor, verification of credential validity confirmed continuity, and the credential had been stolen.",
      "evidence_exhibits": [
        "CHQ-EX-2026-015"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 4",
      "verification_type": "PRIMARY",
      "evidence_class": "E3",
      "source_text": "SN-2026-03-31-01: UNC1069/Axios. Credentials belonging to a legitimate Axios npm maintainer compromised and used to publish malicious Axios versions. Malicious packages bore legitimate maintainer attribution. Registry verification confirmed the publishing credential was valid. Correctness of authorization was not verified. Source: Datadog Security Research."
    },
    {
      "claim_id": "C-05",
      "position_section": "Governance Condition",
      "claim_text": "Authentication at the git push boundary confirmed that the pushing entity possessed valid credentials with push permissions — it did not verify that push option values submitted by the authenticated user would be safely processed by internal backend services.",
      "evidence_exhibits": [
        "CHQ-EX-2026-018"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 5",
      "verification_type": "REINFORCING",
      "evidence_class": "E4",
      "source_text": "SN-2026-05-01-02: GitHub CVE-2026-3854. Unauthenticated network attacker scenario: SSRF via git:// and file:// protocol handler bypass. Authenticated scenario: crafted git push options produce RCE on shared GitHub Actions backend infrastructure. Authentication confirmed the pushing entity had valid credentials. Backend RCE was not within the provenance boundary. Exploited in the wild. Source: Wiz Research / GitHub Security Blog."
    },
    {
      "claim_id": "C-06",
      "position_section": "Governance Condition",
      "claim_text": "An AI gateway holding aggregated credentials for multiple upstream providers presented continuously valid, correctly formatted, properly scoped credentials to upstream providers while itself having been compromised at the authentication layer — upstream providers verified continuity and could not verify correctness.",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ],
      "relevant_sections": "I. Factual Record — Mechanism 6",
      "verification_type": "REINFORCING",
      "evidence_class": "E5",
      "source_text": "SN-2026-05-01-01: LiteLLM CVE-2026-42208. Pre-authentication Server-Side Template Injection in LiteLLM AI gateway (CVSS 9.8). LiteLLM holds aggregated credentials for 100+ LLM providers and internal services. SSTI via /user/auth endpoint achievable without authentication. Credentials held by the compromised gateway remain continuously valid at upstream providers. Source: Sysdig Threat Research."
    },
    {
      "claim_id": "C-07",
      "position_section": "Evidence Basis — Pattern",
      "claim_text": "Six mechanism-independent demonstrations across a forty-five day window, with no shared technical failure class, common actor, or common ecosystem, establish that the continuity/correctness distinction is a structural property of provenance verification systems, not an implementation failure class.",
      "evidence_exhibits": [
        "CHQ-EX-2026-009",
        "CHQ-EX-2026-014",
        "CHQ-EX-2026-015",
        "CHQ-EX-2026-016",
        "CHQ-EX-2026-017",
        "CHQ-EX-2026-018"
      ],
      "relevant_sections": "II. Structural Basis",
      "verification_type": "PATTERN",
      "evidence_class": "PATTERN",
      "source_text": "Pattern across SN-2026-03-19-01, SN-2026-03-20-01, SN-2026-04-30-01, SN-2026-03-31-01, SN-2026-05-01-02, SN-2026-05-01-01. Mechanisms: GitHub Actions tag inheritance, npm postinstall hook authority, OIDC workflow modification, maintainer credential theft, git push pipeline injection, AI gateway credential aggregation. All six demonstrate continuity verification without correctness verification."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-03-19-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-009",
        "CHQ-EX-2026-014"
      ],
      "evidence_note": "Trivy GitHub Actions / TeamPCP Wave 1 — tag reference authority inheritance, confirmed by Wiz and Aqua Security."
    },
    {
      "signal_id": "SN-2026-03-20-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-009"
      ],
      "evidence_note": "GlassWorm Wave 3 / CanisterWorm — npm postinstall hook authority, stolen tokens verified as continuous, confirmed by Aikido / Socket / Endor Labs."
    },
    {
      "signal_id": "SN-2026-04-30-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-017"
      ],
      "evidence_note": "Mini Shai-Hulud (TeamPCP) — OIDC trusted publishing workflow modification, signed packages from official SAP scope, confirmed by ReversingLabs."
    },
    {
      "signal_id": "SN-2026-03-31-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-015"
      ],
      "evidence_note": "UNC1069/Axios — maintainer credential compromise, all registry verification passed, confirmed by Datadog Security Research."
    },
    {
      "signal_id": "SN-2026-05-01-02",
      "signal_type": "SECURITY_RESEARCH",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-018"
      ],
      "evidence_note": "GitHub CVE-2026-3854 — authentication as sole verification primitive, RCE outside provenance boundary, confirmed by Wiz Research / GitHub Security Blog."
    },
    {
      "signal_id": "SN-2026-05-01-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "REINFORCING",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ],
      "evidence_note": "LiteLLM CVE-2026-42208 — AI gateway credential aggregation plane, upstream provider continuity verification without correctness, confirmed by Sysdig Threat Research."
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-009",
      "title": "GlassWorm Supply Chain Cascade: TeamPCP Wave 1–3 and CanisterWorm",
      "temporal_tag": "OPERATIONAL (MARCH 19–25, 2026)"
    },
    {
      "id": "CHQ-EX-2026-014",
      "title": "TeamPCP Wave 1 — Trivy GitHub Actions Compromise: Execution Authority Inheritance Across Five Ecosystems",
      "temporal_tag": "OPERATIONAL (MARCH 19–21, 2026)"
    },
    {
      "id": "CHQ-EX-2026-015",
      "title": "UNC1069/Axios: Portable Developer Identity Cross-Registry Propagation via npm Maintainer Credential Theft",
      "temporal_tag": "OPERATIONAL (MARCH 31 – APRIL 2, 2026)"
    },
    {
      "id": "CHQ-EX-2026-016",
      "title": "LiteLLM CVE-2026-42208: AI Gateway Pre-Authentication Credential Extraction",
      "temporal_tag": "OPERATIONAL (APRIL 24–26, 2026)"
    },
    {
      "id": "CHQ-EX-2026-017",
      "title": "Mini Shai-Hulud (TeamPCP): SAP CAP and PyTorch Lightning Cross-Registry Compromise",
      "temporal_tag": "OPERATIONAL (APRIL 29–30, 2026)"
    },
    {
      "id": "CHQ-EX-2026-018",
      "title": "GitHub CVE-2026-3854: Remote Code Execution via Single Git Push Command",
      "temporal_tag": "OPERATIONAL (MARCH 4 – APRIL 28, 2026)"
    }
  ],
  "notice": [
    "This docket records the primary claim-to-source mappings for CHQ-P-2026-016 v1.0 (Cryptographic Provenance Systems Validate Continuity of Authorization, Not Correctness of Authorization).",
    "Six signals across a forty-five day window demonstrate six independent mechanism classes. Mechanism independence is high: no two signals share a technical failure class, common actor, or common ecosystem.",
    "Four signals classified PRIMARY (C-01 through C-04): each independently sufficient to support the core position claim. Two signals classified REINFORCING (C-05, C-06): each demonstrates the continuity/correctness distinction in an adjacent domain (authentication boundary, credential aggregation).",
    "CCD record — six layers decomposed (tag reference inheritance, postinstall hook authority, OIDC workflow modification, maintainer credential theft, authentication boundary, credential aggregation), all CONFIRMED. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-016 v1.0.",
    "All four PRIMARY signals (SN-2026-03-19-01, SN-2026-03-20-01, SN-2026-04-30-01, SN-2026-03-31-01) independently confirm the core position claim through mechanism-independent demonstrations. Failure mode independence assessed per CCD enforcement protocol: HIGH.",
    "Two REINFORCING signals (SN-2026-05-01-02, SN-2026-05-01-01) extend the position into adjacent domains (git push authentication boundary, AI gateway credential aggregation) without introducing new failure mechanisms. Both carry CONFIRMED source status.",
    "Primary signals compiled from CHQ Classification Log. All signals passed TSEM evaluation. Source independence assessed per CCD enforcement protocol.",
    "Docket issued under CHQ-D-2026-PIG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-020 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-016 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
