logo

Ongoing supply-chain attack 'explicitly targeting' security, dev tools

ID: d63f0257-1f23-5d44-9e3b-68b6ec0866c3

STIX ID: report--d63f0257-1f23-5d44-9e3b-68b6ec0866c3

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-27

Date Updated: 2026-04-28

Author: Jessica Lyons

...
...

Checkmarx confirmed a March 23 supply-chain incident tied to TeamPCP/Lapsus$ in which credential‑stealing malware—originating from a prior Trivy compromise—was used to poison KICS and other developer tooling, exfiltrate source code, API keys, database credentials and employee data, and compromise GitHub Actions, Open VSX plugins and Bitwarden's CLI, creating a broad downstream blast radius and potential follow‑on extortion/ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.