Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
ID: 41ea6f12-44db-566c-831c-17d9d6988628
STIX ID: report--41ea6f12-44db-566c-831c-17d9d6988628
Feed Name: The Register (Security)
Two March supply-chain compromises of widely used open-source projects (Trivy and Axios) injected credential-stealing malware into installer artifacts and CI/CD pipelines, enabling exfiltration of CI/CD secrets, cloud credentials, SSH keys, and developer configuration files. One incident is attributed to a suspected North Korean actor (UNC1069) using highly targeted AI-enabled social engineering to compromise a maintainer; the other is linked to a criminal group, TeamPCP, which used stolen secrets to push malicious updates across multiple projects and likely impacted credentials for over 10,000 organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
