Earlier quoted context omitted.
Techies aren't immune either, before we all follow the "blame management" bandwagon for the 2^101-tieth time. CEOs aren't the reason supply chain attacks are absolutely rife with problems right now. That's entirely on the technical experts who created all of those pinnacle achievements in tech ranging from tech-led orgs and open source community built package ecosystems. Arbitrary code execution in homebrew, scoop, c…
Wait, where can we read more about that? When you say "the keys to prod" do you mean the prod .ENV variables, or something else?
An employee (dev/sysadmin) had their home device compromised via a supply chain attack, which installed a keylogger and the attacker(s) were able to exfiltrate the credentials to lastpass cloud envs.