logo

Chain Reaction: How One Stolen Token Tore Through Five Ecosystems

ID: 081dc615-5b26-5b85-a025-70da22cbddf0

STIX ID: report--081dc615-5b26-5b85-a025-70da22cbddf0

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Eli Nesterov

...
...

TeamPCP was a large 2026 supply-chain campaign that exploited a Trivy GitHub Actions misconfiguration to steal a PAT and pivot across five ecosystems (GitHub Actions, npm, Docker Hub, PyPI, OpenVSX), leading to malicious package/image publication, a self-propagating npm worm, a Kubernetes wiper, and ~54GB of exfiltrated data affecting thousands of organizations; the report attributes the scale to pervasive static credentials and recommends discovery and replacement with short‑lived cryptographic identities (SPIFFE, OIDC) alongside standard supply‑chain mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.