logo

Software supply chain hacks trigger wave of intrusions, data theft

ID: 1819c5ec-056b-5976-80bf-f62c86512837

STIX ID: report--1819c5ec-056b-5976-80bf-f62c86512837

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

The report describes a series of widespread supply-chain attacks attributed to TeamPCP and a North Korean actor (UNC1069) that compromised popular packages (Axios npm, Trivy, KICS, LiteLLM, Telnyx), resulting in stolen secrets and credentials that were rapidly used to perform cloud environment intrusions, exfiltrate data, and deploy a remote access trojan across Windows, macOS, and Linux; the compromises have global impact across many industries and are linked to follow-on ransomware, extortion, and cryptocurrency theft activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.