Advertisement
TeamPCP Supply Chain: Checkmarx Wider Scope & LiteLLM PyPI Compromise
An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.
Risks of AI-Driven Dependency Resolution and Software Maintenance
AI models often hallucinate version numbers and ignore security fixes during dependency resolution, increasing technical debt and supply chain risks.
TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code
TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.
FCC Bans Foreign-Made Routers Over National Security Concerns
The FCC has prohibited the importation of new foreign-made routers to mitigate supply chain risks and protect critical communication infrastructure from adversaries.
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.
LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials
TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.
npm Ghost Campaign: 7 Malicious Packages Steal Crypto Wallets
ReversingLabs uncovers the Ghost campaign targeting developers with 7 malicious npm packages designed to exfiltrate cryptocurrency wallets and credentials.
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.
Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.
Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub
Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.
Trivy Supply Chain Attack Spreads CanisterWorm via 47 npm Packages
Attackers compromise 47 npm packages using CanisterWorm, a self-propagating threat leveraging ICP canisters following a major Trivy supply chain attack.
trivy-action Supply Chain Attack: Scattered Swarm Steals GitHub Secrets
Analysis of the trivy-action supply chain compromise by Scattered Swarm. Learn how GitHub runner secrets were stolen and critical mitigation steps.
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.
GlassWorm Supply Chain Attack: 400+ Malicious Repos Identified
The GlassWorm campaign hits GitHub, npm, and VSCode marketplaces with over 400 malicious repositories. Learn to detect and mitigate this supply chain threat.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.
GlassWorm: Stolen GitHub Tokens Fuel Python Malware Injection
The GlassWorm campaign uses stolen GitHub tokens to inject malicious code into Python repositories, including Django and machine learning projects.
ForceMemo: Credential Theft Compromises Python Repositories
Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.
AppsFlyer Web SDK Hijacked to Deliver Crypto-Stealing Malware
AppsFlyer's Web SDK was compromised in a supply chain attack to steal cryptocurrency. Learn how to detect and mitigate this JavaScript injection threat.
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.
UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access
UNC6426 leveraged stolen GitHub tokens from the nx npm compromise to achieve full AWS administrative control and data exfiltration within 72 hours.