logo

Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise

ID: 41ea6f12-44db-566c-831c-17d9d6988628

STIX ID: report--41ea6f12-44db-566c-831c-17d9d6988628

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Two March supply-chain compromises of widely used open-source projects (Trivy and Axios) injected credential-stealing malware into installer artifacts and CI/CD pipelines, enabling exfiltration of CI/CD secrets, cloud credentials, SSH keys, and developer configuration files. One incident is attributed to a suspected North Korean actor (UNC1069) using highly targeted AI-enabled social engineering to compromise a maintainer; the other is linked to a criminal group, TeamPCP, which used stolen secrets to push malicious updates across multiple projects and likely impacted credentials for over 10,000 organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.