Defending against TeamPCP software supply chain attacks | Threat Intelligence
ID: 76c67f6e-1ed7-5249-bca7-6e191a900baf
STIX ID: report--76c67f6e-1ed7-5249-bca7-6e191a900baf
Feed Name: Threat Intelligence | Blog | Okta
The report details 2025 supply‑chain attacks in which threat actors used targeted email phishing and Adversary‑in‑the‑Middle (AitM) techniques — and in one case credential‑stealing malware — to compromise npm and PyPI maintainer accounts, create API tokens or update packages, and publish malicious releases that intercepted or redirected cryptocurrency transactions. It highlights the rapid discovery of such malicious updates, the systemic risk to downstream users, and recommends mitigations such as release cooldowns, SBOMs, software composition analysis, GitHub Actions SHA‑pinning, multi-approval merge policies, commit signing, and phishing‑resistant authentication (passkeys/security keys).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
