The Domino Effect of a Software Supply Chain Attack
ID: aeeba0f9-cb67-55fe-b918-82829162f41a
STIX ID: report--aeeba0f9-cb67-55fe-b918-82829162f41a
Feed Name: Mitiga
TeamPCP executed a fast, multi‑ecosystem software supply‑chain campaign in March 2026 that began with a pull request abusing GitHub Actions (pull_request_target) to steal a service account PAT, then used rewritten git tags and cached tokens to distribute malicious Trivy Docker images, publish compromised npm and PyPI packages (including backdoors using .pth files and the CanisterWorm ICP-based C2), and attempt Kubernetes lateral movement; the report includes IOCs, concrete detection logic for each attack phase, and guidance for cross‑platform correlation to turn isolated alerts into a coherent investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
