#supplychainattacks
#Supplychainattacks targeting security and developer tools continue, with #SAP, #Intercom, and #lightning #npmpackages compromised. The attacks, attributed to TeamPCP, involve credential-stealing malware that self-propagates, encrypts stolen data, and exfiltrates it to a new GitHub repository.…
May 2, 2026 at 9:41 AM
TeamPCP has shifted its focus from cloud exploitation to large-scale supply chain attacks #TeamPCP #SupplyChainAttacks https://threatmon.io/teampcp-how-a-cloud-exploitation-group-evolved-into-a-supply-chain-threat/
TeamPCP: How a Cloud Exploitation Group Evolved Into a Supply Chain Threat - ThreatMon
threatmon.io
August 1, 2026 at 6:28 AM
Supply-chain attacks on open source software are getting out of hand https://arstechni.ca... #supplychainattacks #repositories #opensource #Security #Biz&IT
July 25, 2025 at 7:03 PM
Software packages with more than 2 billion weekly downloads hit in supply-chain attack https://arstechni.ca... #supplychainattacks #supplychain #opensource #Security #Biz&IT #npm
September 9, 2025 at 2:00 AM
Mitigate Supply Chain Attacks ⚠️ Prevent threats from compromised vendors with strong risk controls, monitoring, and zero-trust security.

Tap the link to know more: bit.ly/4fQkJ4G

#SupplyChainAttacks #PotatoSecurity #DataProtection #InfoSec
April 28, 2026 at 9:15 AM
Very timely study providing additional evidence about the cyber risks of downloading and using third parties' AI models. On the importance of investing in AI Security Governance
www.helpnetsecurity.com/2025/10/03/r... #AI #AIModels #Risks #cybersecurity #SupplyChainAttacks #AISecurityGovernance
When loading a model means loading an attacker - Help Net Security
Attackers can hide malicious code in shared machine learning models. Learn how to manage machine learning model security and protect systems.
www.helpnetsecurity.com
October 3, 2025 at 7:04 PM
#BeerDrivenDevs EP63: It’s Time to Let #JavaScript Go

Not a hot take. We follow the thread from #SupplyChainAttacks through culture, incentives, and governance to the uncomfortable truth.

JavaScript isn’t going away. But for us, the conclusion isn’t ambiguous anymore.

Links in comments 👇
January 20, 2026 at 10:40 PM
Had me excited with the intro. *sigh*

Hate to see it, but I have yet to see a justified reason to ask for my #biometrics or drivers license.

Much less in order to use an application IVE BEEN USING FOR NEARLY A DECADE.

Esp considering #Discord’s history & the prevalence in #supplychainattacks. 🥶
For those looking for a good alternative to Discord:

There isn't one.
There's nothing that does exactly what Discord does in the way that Discord does it. Sorry for the bad news. There's a reason we still use Discord despite all the past bullshit.
February 10, 2026 at 6:25 AM
Google Analyst Infiltrated TeamPCP and Helped Disrupt Its Supply-Chain Attacks

🤖 IA: It's not clickbait ✅
👥 Users: It's not clickbait ✅

#supplychainattacks #teampcp

👇👇👇
Google Analyst Infiltrated TeamPCP and Helped Disrupt Its Supply-Chain Attacks
Google Threat Intelligence Group has revealed that a Mandiant analyst infiltrated TeamPCP, a hacking group accused of carrying out an unusually extensive series of software supply-chain attacks. The analyst spent months building trust with a TeamPCP member and gained access to an internal chat used by roughly a dozen people at the center of the operation. This access gave Google visibility into the group's activities and helped the company warn potential victims and disrupt further attacks. TeamPCP, which appears to have emerged online in late 2025, repeatedly compromised open-source software and developer accounts to distribute malware and obtain additional credentials. Its targets reportedly included tools and companies such as Trivy, LiteLLM, Checkmarx, TanStack, and Mistral AI. The campaign eventually affected more than a thousand companies and exposed credentials belonging to hundreds of thousands of users. The group also used a self-spreading worm called Mini Shai-Hulud to automate parts of the operation. Google says its undercover analyst discovered a server containing stolen usernames, passwords, and access tokens. Rather than contacting every affected organization individually, Google first worked with major service providers, including Amazon Web Services and Microsoft, to revoke compromised credentials and limit the hackers' ability to use them. Google also discovered an AI-assisted zero-day exploit being developed by someone in the group's circle. After testing the exploit, Google alerted the affected software developer, who patched the vulnerability. The investigation also benefited from a split between TeamPCP and the cybercriminal group ShinyHunters, which provided Google with chat logs. Separately, Google researchers traced digital clues linking a TeamPCP member to an email account and a Google Drive containing stolen material. The information was passed to the FBI and contributed to the investigation that preceded the arrests in Australia of Ruben Ian Thomson and Louis Michael Gaebler. Google says its undercover analyst did not participate in illegal hacking and only observed the group's activities while maintaining the cover.
en.killbait.com
September 18, 2026 at 9:11 PM
Shai-Hulud now targets 469 credential spots—package tokens and production secrets are at highest risk. #Security #DevSecOps #SupplyChainAttacks #CredentialSecurity #ShaiHulud #CyberRisk https://thedailytechfeed.com/shai-hulud-infostealer-now-targets-469-credential-locations/
September 3, 2026 at 11:36 AM