logo

Defending against TeamPCP software supply chain attacks | Threat Intelligence

ID: 589191a1-fe92-52f7-91a7-d1b2ea772560

STIX ID: report--589191a1-fe92-52f7-91a7-d1b2ea772560

Feed Name: Okta Threat Intelligence

Threat Score
78/100

Date Published: 2026-05-17

Date Updated: 2026-08-05

Author: Jeremy Kirk, George Wang

...
...

The report describes targeted phishing and credential‑stealing campaigns that compromised npm and PyPI maintainer accounts in 2025, enabling attackers to publish malicious package updates (e.g., replacing cryptocurrency wallets and releasing trojanized packages). It highlights attack vectors including AitM-style phishing and GitHub Actions pull_request_target abuse, documents active exploitation of popular packages, and recommends mitigations such as cooldown windows, SBOMs, dependency audits, SHA pinning for Actions, and phishing‑resistant authentication (passkeys/security keys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.