Chain Reaction: How One Stolen Token Tore Through Five Ecosystems
ID: 081dc615-5b26-5b85-a025-70da22cbddf0
STIX ID: report--081dc615-5b26-5b85-a025-70da22cbddf0
Feed Name: Security Boulevard
TeamPCP was a large 2026 supply-chain campaign that exploited a Trivy GitHub Actions misconfiguration to steal a PAT and pivot across five ecosystems (GitHub Actions, npm, Docker Hub, PyPI, OpenVSX), leading to malicious package/image publication, a self-propagating npm worm, a Kubernetes wiper, and ~54GB of exfiltrated data affecting thousands of organizations; the report attributes the scale to pervasive static credentials and recommends discovery and replacement with short‑lived cryptographic identities (SPIFFE, OIDC) alongside standard supply‑chain mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
