logo

Defending against TeamPCP software supply chain attacks | Threat Intelligence

ID: 76c67f6e-1ed7-5249-bca7-6e191a900baf

STIX ID: report--76c67f6e-1ed7-5249-bca7-6e191a900baf

Feed Name: Threat Intelligence | Blog | Okta

Threat Score
78/100

Date Published: 2026-05-17

Date Updated: 2026-07-16

Author: Jeremy Kirk, George Wang

...
...

The report details 2025 supply‑chain attacks in which threat actors used targeted email phishing and Adversary‑in‑the‑Middle (AitM) techniques — and in one case credential‑stealing malware — to compromise npm and PyPI maintainer accounts, create API tokens or update packages, and publish malicious releases that intercepted or redirected cryptocurrency transactions. It highlights the rapid discovery of such malicious updates, the systemic risk to downstream users, and recommends mitigations such as release cooldowns, SBOMs, software composition analysis, GitHub Actions SHA‑pinning, multi-approval merge policies, commit signing, and phishing‑resistant authentication (passkeys/security keys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.