Defending against TeamPCP software supply chain attacks | Threat Intelligence
ID: 589191a1-fe92-52f7-91a7-d1b2ea772560
STIX ID: report--589191a1-fe92-52f7-91a7-d1b2ea772560
Feed Name: Okta Threat Intelligence
The report describes targeted phishing and credential‑stealing campaigns that compromised npm and PyPI maintainer accounts in 2025, enabling attackers to publish malicious package updates (e.g., replacing cryptocurrency wallets and releasing trojanized packages). It highlights attack vectors including AitM-style phishing and GitHub Actions pull_request_target abuse, documents active exploitation of popular packages, and recommends mitigations such as cooldown windows, SBOMs, dependency audits, SHA pinning for Actions, and phishing‑resistant authentication (passkeys/security keys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
