Defending against TeamPCP software supply chain attacks | Threat Intelligence
ID: 11621f90-fa32-5373-921b-57229c7438e8
STIX ID: report--11621f90-fa32-5373-921b-57229c7438e8
Feed Name: Okta Threat Intelligence
The report describes 2025 supply-chain attacks targeting open-source maintainers: a targeted phishing campaign that compromised an npm maintainer and injected crypto‑theft code into multiple packages, and AitM phishing against PyPI users that yielded API tokens and malicious num2words releases. It highlights how attacker control of maintainer accounts and mutable CI/workflow dependencies (e.g., pull_request_target, unpinned action tags) enable widespread impact, and provides mitigations including release cooldowns, SBOMs, SCA tools, GitHub Actions SHA pinning, multi-approval policies, and adoption of phishing-resistant authentication such as passkeys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
