logo

Defending against TeamPCP software supply chain attacks | Threat Intelligence

ID: 11621f90-fa32-5373-921b-57229c7438e8

STIX ID: report--11621f90-fa32-5373-921b-57229c7438e8

Feed Name: Okta Threat Intelligence

Threat Score
70/100

Date Published: 2026-05-17

Date Updated: 2026-08-05

Author: Jeremy Kirk, George Wang

...
...

The report describes 2025 supply-chain attacks targeting open-source maintainers: a targeted phishing campaign that compromised an npm maintainer and injected crypto‑theft code into multiple packages, and AitM phishing against PyPI users that yielded API tokens and malicious num2words releases. It highlights how attacker control of maintainer accounts and mutable CI/workflow dependencies (e.g., pull_request_target, unpinned action tags) enable widespread impact, and provides mitigations including release cooldowns, SBOMs, SCA tools, GitHub Actions SHA pinning, multi-approval policies, and adoption of phishing-resistant authentication such as passkeys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.