# CHQ-ED-2026-021

- **Artifact ID:** CHQ-ED-2026-021
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-021
- **Machine-record SHA-256:** `e59b6e4ac4745e449809a3385918ada743a53f9293b4ef1a1f8f4f934d610739`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-021",
  "associated_position": "CHQ-P-2026-016 V1.1",
  "relationship": "supplementary",
  "issuance_date": "2026-07-24",
  "evidence_freeze_time": "2026-07-24T00:00:00Z",
  "total_exhibits": 1,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "A coordinated campaign held several publishing pipelines and several OIDC publishing identities simultaneously. Each identity was individually valid and individually authorized to publish. Provenance verification confirmed that packages were published by identities entitled to publish them. It did not confirm, and structurally could not confirm, that the parties exercising those identities were the parties the identities belonged to.",
      "evidence_exhibits": [
        "CHQ-EX-2026-023"
      ],
      "relevant_sections": "I. Factual Record — Publishing Identity Scope, Provenance State",
      "verification_type": "PRIMARY",
      "evidence_class": "E1",
      "source_text": "SN-2026-07-15-01: AsyncAPI npm ecosystem. Multiple official packages backdoored through two compromised source repositories plus a further independent repository compromise. Multiple OIDC publishing identities abused across release branches. Shared infrastructure and malware across pipelines reported as basis for single-campaign assessment. Source: Upwind managed detection and response research."
    },
    {
      "claim_id": "C-02",
      "position_section": "Governance Condition",
      "claim_text": "The payload executed at package import rather than through installation lifecycle scripts. Verification and scanning that inspects installation behavior did not evaluate the executed code path. Continuity of the publishing chain was confirmed by the same verification that did not reach the execution surface.",
      "evidence_exhibits": [
        "CHQ-EX-2026-023"
      ],
      "relevant_sections": "I. Factual Record — Execution Vector, Downstream Exposure",
      "verification_type": "REINFORCING",
      "evidence_class": "E1",
      "source_text": "SN-2026-07-15-01: Execution at import time rather than preinstall or postinstall. Public reporting recorded the property as deliberate evasion of install-focused scanning. Developer workstations and continuous integration runners importing affected versions were to be treated as potentially compromised. Source: Upwind managed detection and response research."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-07-15-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-023"
      ],
      "evidence_note": "AsyncAPI npm campaign — parallel OIDC publishing identity compromise, provenance valid throughout, import-time execution. Reported by Upwind managed detection and response research."
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-023",
      "title": "AsyncAPI: Parallel Publishing-Identity Compromise with Import-Time Execution",
      "temporal_tag": "OPERATIONAL (JULY 2026)"
    }
  ],
  "notice": [
    "This docket records supplementary claim-to-source mappings for CHQ-P-2026-016 v1.1 (Cryptographic Provenance Systems Validate Continuity of Authorization, Not Correctness of Authorization). The primary mappings for this position are recorded in CHQ-ED-2026-020 v1.0 and are not restated here.",
    "This docket rests on a single signal from a single primary source. Signal independence is not assessed and is not claimed. The mechanism recorded here belongs to the same mechanism class established by the six independent demonstrations in CHQ-ED-2026-020; it extends that class with a campaign exhibiting parallel publishing-identity redundancy, which the prior demonstrations did not exhibit.",
    "CCD record — three layers decomposed (parallel identity compromise, provenance validity throughout, import-time execution), all CONFIRMED against the primary source. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH. The signal conforms closely to the position it supports and was classified under inverted burden accordingly; it is recorded as REINFORCING at the docket level and does not alter the position’s evidence state."
  ],
  "integrity_statement": [
    "This docket records supplementary claim-to-source mappings for CHQ-P-2026-016 v1.1.",
    "One signal, classified PRIMARY at intake, is mapped to two claims. Source independence is not established: both claims derive from a single research publication. Corroborating industry reporting was contemporaneous but not independently investigative.",
    "The position’s evidence state, signal count, and vector count at v1.0 are unchanged by this docket. This docket is supplementary and does not amend the position’s canonical evidence basis.",
    "Primary signal compiled from CHQ Classification Log. Signal passed TSEM evaluation. Source independence assessed per CCD enforcement protocol and recorded as NOT ESTABLISHED.",
    "Docket issued under CHQ-D-2026-PIG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-021 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-016 v1.1 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
