CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

TeamPCP

actor · actor:teampcp single-source

Threat actor targeting software supply chains; operator of the Mini Shai-Hulud npm worm family and the SANDCLOCK Checkmarx Jenkins-plugin backdoor, with victims including OpenAI.

Coverage
16
first 2026-05-06 → last 2026-08-28
Latest activity
2026-08-28
A law-enforcement disruption of the Shai-Hulud npm-worm operator, with AFP's own scale estimate now on the…
Peak priority
high
7 high · 9 notable
Targets
technology
sectors: technology, public-sector, education · regions: europe, switzerland
Sources cited
69
35 hosts
2026-05-1216 appearances2026-08-28

Action items (2)

Do-now tasks recorded on the entries about TeamPCP, newest first. Check the date before acting on an older one.

  • Re-scope any audit that was closed on the question 'did we install litellm 1.82.7 or 1.82.8 on 24 March': check instead whether CI workflows referenced aquasecurity/trivy-action or aquasecurity/setup-trivy by mutable version tag rather than a full commit SHA in the second half of March 2026, and whether any host pulled the aquasec/trivy image tags 0.69.4, 0.69.5, 0.69.6 or latest between 19 March 18:24 UTC and 23 March 01:36 UTC per Docker's own stated window. Treat credentials reachable from those runners as exposed.
    2026-08-15SOCRadar's row-level re-analysis moves the blast…
  • Inventory Model Context Protocol endpoints in your cloud estate and confirm each one requires authentication, Wiz found unauthenticated MCP endpoints across hundreds of environments, and each is a pre-authenticated proxy already holding the backend credentials it bridges.
    2026-08-08The AI toolchain became a cloud attack surface with…

Defender insights

What each entry about TeamPCP tells a defender to do, newest first.

2026-08-15NOTABLESOCRadar's row-level re-analysis moves the blast radius upstream to a compromised security scanner, which changes what a CI/CD estate has to audit

Triage

2026-08-08NOTABLEThe AI toolchain became a cloud attack surface with its own recurring vulnerability cadence, and the credentials it holds are non-human

2026-07-14NOTABLETalos catalogues where malicious Python packages execute code across the install lifecycle, including persistent .pth and site-hook footholds

Triage

2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand

Detection

2026-05-12HIGHGTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Story timeline

  1. 2026-08-28AFP-FBI-WAPF disrupt TeamPCP: two Western Australia men charged over the npm/GitHub supply-chain worm operation AFP estimates compromised 1,000+ organisations, 500,000+ credentials and 300+ GB of data
    active-threatsA law-enforcement disruption of the Shai-Hulud npm-worm operator, with AFP's own scale estimate now on the public record
  2. 2026-08-15The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
    active-threatsSOCRadar's row-level re-analysis moves the blast radius upstream to a compromised security scanner, which changes what a CI/CD estate has to audit
  3. 2026-08-08Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
    researchThe AI toolchain became a cloud attack surface with its own recurring vulnerability cadence, and the credentials it holds are non-human
  4. 2026-07-14Cisco Talos maps the full taxonomy of Python-package build-time and import-time code execution ("The Serpent's Tongue")
    researchTalos catalogues where malicious Python packages execute code across the install lifecycle, including persistent .pth and site-hook footholds
  5. 2026-06-12npm v12 will disable install scripts by default, audit CI/CD pipelines before July
    research
  6. 2026-06-09TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
    active-threats
  7. 2026-06-02"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
    active-threats
  8. 2026-05-28Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
    deep-dive
  9. 2026-05-24Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
    deep-dive
  10. 2026-05-24npm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm waves
    active-threats
  11. 2026-05-21Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years
    deep-dive
  12. 2026-05-15Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
    research
  13. 2026-05-15Datadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source code
    active-threats
  14. 2026-05-13Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
    deep-dive
  15. 2026-05-12TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
    trending-vulnerabilitiesTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK
  16. 2026-05-12GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
    deep-dive
ATT&CK techniques (35 across 13 tactics)

35 techniques observed across 12 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceSearch Open Websites/Domains
  • Resource DevelopmentAcquire Infrastructure: Domains
  • Initial AccessValid Accounts · Valid Accounts: Cloud Accounts · Exploit Public-Facing Application · Supply Chain Compromise · Supply Chain Compromise: Compromise Software Dependencies and Development Tools · Supply Chain Compromise: Compromise Software Supply Chain · Trusted Relationship
  • ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python · Command and Scripting Interpreter: JavaScript · User Execution · User Execution: Malicious File · Hijack Execution Flow: Path Interception by PATH Environment Variable
  • PersistenceValid Accounts · Valid Accounts: Cloud Accounts · Server Software Component: Web Shell · Boot or Logon Autostart Execution: XDG Autostart Entries
  • Privilege EscalationValid Accounts · Valid Accounts: Cloud Accounts · Boot or Logon Autostart Execution: XDG Autostart Entries
  • StealthObfuscated Files or Information · Masquerading · Masquerading: Match Legitimate Resource Name or Location · Valid Accounts · Valid Accounts: Cloud Accounts · Deobfuscate/Decode Files or Information · Hijack Execution Flow: Path Interception by PATH Environment Variable
  • Defense ImpairmentSubvert Trust Controls · Subvert Trust Controls: Code Signing
  • Credential AccessOS Credential Dumping: Proc Filesystem · Brute Force · Unsecured Credentials · Unsecured Credentials: Credentials In Files · Credentials from Password Stores · Forge Web Credentials: SAML Tokens
  • DiscoveryFile and Directory Discovery
  • CollectionData from Cloud Storage
  • Command and ControlApplication Layer Protocol · Application Layer Protocol: Web Protocols
  • ExfiltrationExfiltration Over Web Service

Reconnaissance TA0043

T1593Search Open Websites/Domains×1

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Resource Development TA0042

T1583.001Acquire Infrastructure: Domains×1

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1195Supply Chain Compromise×3

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · ATT&CK page ↗

T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×3

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×6

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×2

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-06-02/miasma-worm-backdoors-32-red-hat-cloud-services-npm-packages · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1574.007Hijack Execution Flow: Path Interception by PATH Environment Variable×1

Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1547.013Boot or Logon Autostart Execution: XDG Autostart Entries×1

Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login. XDG Autostart entries are available for any XDG-compliant Linux system. XDG Autostart entries use Desktop Entry files (`.desktop`) to configure the user’s desktop environment upon user login. These configuration files determine what applications launch upon user login, define associated applications to open specific file types, and define applications used to open removable media.

Evidence: 2026-06-02/miasma-worm-backdoors-32-red-hat-cloud-services-npm-packages · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1547.013Boot or Logon Autostart Execution: XDG Autostart Entries×1

Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login. XDG Autostart entries are available for any XDG-compliant Linux system. XDG Autostart entries use Desktop Entry files (`.desktop`) to configure the user’s desktop environment upon user login. These configuration files determine what applications launch upon user login, define associated applications to open specific file types, and define applications used to open removable media.

Evidence: 2026-06-02/miasma-worm-backdoors-32-red-hat-cloud-services-npm-packages · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×4

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1574.007Hijack Execution Flow: Path Interception by PATH Environment Variable×1

Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

Defense Impairment TA0112

T1553Subvert Trust Controls×1

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Credential Access TA0006

T1003.007OS Credential Dumping: Proc Filesystem×1

Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc/<PID>/maps` file shows how memory is mapped within the process’s virtual address space. And `/proc/<PID>/mem`, exposed for debugging purposes, provides access to the process’s virtual address space.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1552Unsecured Credentials×5

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-08-28/teampcp-afp-fbi-disruption-shai-hulud-arrests · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×6

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-06-02/miasma-worm-backdoors-32-red-hat-cloud-services-npm-packages · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Entries about TeamPCP (16)

2026-08-28 · view entry permalink →

NOTABLEupdatedNATOA1

AFP-FBI-WAPF disrupt TeamPCP: two Western Australia men charged over the npm/GitHub supply-chain worm operation AFP estimates compromised 1,000+ organisations, 500,000+ credentials and 300+ GB of data

The Australian Federal Police, FBI and Western Australia Police Force jointly announced on 2026-08-27 that two Western Australian men, aged 21 and 23, were charged with a combined 14 Commonwealth cybercrime offences (unauthorised data modification with intent to commit a serious offence, supplying data with intent to commit a computer offence, dealing with proceeds of crime over AUD 100,000, and, for one defendant, failing to comply with a section 3LA data-access order) following parallel AFP/FBI investigations that began in April 2026 after multiple threat-intelligence vendors reported a supply-chain-poisoning syndicate.

AFP states the syndicate "allegedly inserted malicious code into software available on an open-source repository, which was then unwittingly used by other developers," with infected software subsequently distributed into "computer systems at other organisations across government, academia and the private sector," enabling theft of user credentials and authentication material. AFP's own estimate: "it is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data" (Australian Federal Police, 2026-08-27), with remediation costs in the hundreds of millions of dollars. FBI Cyber Division names the group directly: "these men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide" (FBI Cyber Division Assistant Director Brett E. Leatherman, 2026-08-27).

KrebsOnSecurity, which had independently identified one of the defendants, the group's self-described spokesperson, in June and interviewed him extensively via Signal, corroborates and adds operational-model detail: TeamPCP's core tactic is cyclical, compromising a developer's credentials to insert malicious code into a widely-depended-upon open-source package, harvesting the credentials of downstream developers who install it, and repeating against the next package, powered principally by the self-propagating "Shai-Hulud" worm (three iterations to date, whose source TeamPCP itself open-sourced). Prior TeamPCP campaigns already tracked by named security vendors include the March 2026 compromise of the LiteLLM open-source AI gateway (CloudSEK: 2,500+ organisations' cloud-service keys and CI/CD secrets harvested) and a May 2026 claim of roughly 3,800 compromised GitHub repositories.

Google's Threat Intelligence Group characterises TeamPCP's structure directly. Austin Larsen says "It is not a structured criminal crew with a single operator" and "It is a peer community of individually-skilled actors, with one clear center of gravity" (Austin Larsen, Google Threat Intelligence Group, via KrebsOnSecurity, 2026-08-27), tracing its likely primary operator's residential/mobile internet connections to South Africa during at least some of its attacks. Investigators note further arrests are not ruled out; both defendants were held in custody pending an 18 September court date.

The arrests do not change the remediation guidance already published for the LiteLLM/Trivy and coding-agent CI-harness campaigns attributed to the same actor; a decentralised peer community losing two participants does not retire the worm's self-propagating infrastructure or the copycat variants it has already spawned; the standing guidance on pinning dependencies and auditing for Shai-Hulud-family indicators still applies.

It is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data.

These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide.

Australian Federal Police

It is not a structured criminal crew with a single operator

It is a peer community of individually-skilled actors, with one clear center of gravity.

Austin Larsen (Google Threat Intelligence Group), via KrebsOnSecurity
Correctionrun 2026-09-29T2134Z-auditevidenceheadlinebody

Neither the Australian Federal Police release nor KrebsOnSecurity describes the arrests as the first law-enforcement action against TeamPCP (Australian Federal Police, 2026-08-27; KrebsOnSecurity, 2026-08-27), and the entry no longer calls them that. The scale estimate, the charges and the assessment of the group's structure are unchanged.

incident28 Aug 06:08Zmulti-sourceOpen finding →

2026-08-15 · view entry permalink →

NOTABLENATOB1

The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned

The widely reported figure (more than 2,500 organisations compromised through poisoned LiteLLM packages) turns out to describe the wrong artifact for almost all of them. SOCRadar re-analysed the exposure dataset row by row and found that "For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry" (SecurityWeek, 2026-08-14 · SOCRadar, 2026-08-13). Collection that stops before the malicious packages exist cannot have come from them. SOCRadar times the start against the upstream event instead: the earliest collection record sits eighteen minutes after the poisoned Trivy build published, activity surged while malicious Trivy images were live on Docker Hub, and it closed once the registry quarantined the LiteLLM packages (SecurityWeek, 2026-08-14).

The upstream compromise is documented by the vendor itself. Aqua Security's incident advisory records that on 19 March "The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits", publishing a malicious Trivy build at the same time (Aqua Security, 2026-04-01). LiteLLM's own maintainers state the connection plainly: "We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow" (LiteLLM, 2026-03-24). A security scanner is an unusually good place to put credential-stealing code, because it is a tool organisations deliberately run inside their build systems with access to the material they are scanning.

One detail from Aqua's write-up deserves to outlive this incident. The poisoned tags carried GitHub's "Immutable" badge: "The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the 'Immutable' indicator. Pinning to full commit SHAs remains the only truly immutable protection" (Aqua Security, 2026-04-01). A control that displayed as satisfied while being subverted is worse than an absent one, because it ends the review.

What the correction is worth to this constituency is visible in one of the confirmed victims. CERT-EU assesses "with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP", in an intrusion into a European Commission cloud account from which "A significant volume of data (about 91.7 GB compressed) was exfiltrated ... including personal data such as names, email addresses, and email content" (CERT-EU, 2026-04-02). That is an EU institution reached through a build-pipeline dependency, not through a package a developer chose to install.

Triage: a security scanner reaching out during a build is normal behaviour, so egress from the runner is not by itself the discriminator. What separates this from a healthy pipeline is the pairing of a scanner invocation with credential-store and environment reads it has no reason to make, and outbound traffic to a destination that is not the scanner's own update or vulnerability-database endpoint, with the reference in the workflow file being a mutable tag rather than a commit SHA as the precondition that made it possible.

For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry.

SecurityWeek, citing SOCRadar

March 19, 2026 (~17:43 UTC): The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits.

Aqua Security 2026-04-01

We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow.

LiteLLM (BerriAI) 2026-03-24

GitHub's release UI displayed "Immutable" badges next to each poisoned tag. The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the "Immutable" indicator. Pinning to full commit SHAs remains the only truly immutable protection.

Aqua Security 2026-04-01

We assess with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP.

CERT-EU 2026-04-02

Builds on: The AI gateway's own extension points become the tamper surface, and reverting the config…

threat15 Aug 06:20Zmulti-sourceOpen finding →

2026-08-08 · view entry permalink →

NOTABLENATOB2

Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people

Wiz Research's semi-annual cloud threat report covers January to June 2026, and its value for this constituency is the named inventory rather than the trend lines: it says concretely which AI infrastructure attracted attacker and researcher attention, and what the resulting exposure looks like in a cloud estate.

The AI toolchain now has its own vulnerability cadence. LiteLLM (an AI gateway Wiz says is present in over a third of the cloud environments it monitors) "had four separate security events in six months: a supply-chain compromise, an SQL injection vulnerability exploited in the wild, a privilege escalation chain and an authentication bypass", while Dify, Langflow, n8n and Ollama "each had critical unauthenticated vulnerabilities of their own" (Wiz Research, 2026-08-06). That list is worth reading as an asset-inventory prompt: these are components teams stand up quickly, often outside the change process that governs the rest of the estate, and three of the five have already reached this pipeline's coverage through separate exploited-vulnerability events.

The exposure finding is sharper than the vulnerability one. On Model Context Protocol servers, Wiz reports: "We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services" (Wiz Research, 2026-08-06). The reason that shape matters is that an MCP server is not a data store to be broken into; it is a component that already holds the credentials for everything behind it and exists to act on their behalf, so reaching it unauthenticated is not a step toward access, it is the access.

On the actor side, Wiz profiles JINX-0163, a cloud-native extortion group it began tracking in 2026 and that "consistently targets non-human identities - service accounts and IAM roles - rather than end users", in some cases leveraging a single over-privileged identity or an exposed state file to pivot to a full inventory (Wiz Research, 2026-08-06). An extortion group that skips human identity entirely bypasses most of the control stack organisations have spent two years building (phishing-resistant MFA, conditional access, helpdesk verification) none of which applies to a service account.

On supply chain, Wiz records that notable supply-chain attacks "went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026", with TeamPCP, North Korea and at least three independent operations running campaigns concurrently across npm, PyPI, Composer, VSCode extensions, Jenkins plugins and AUR, several of which had not been targeted this way before (Wiz Research, 2026-08-06). It also notes that malicious packages' shrinking availability window is what makes an install cooldown policy effective (declining to download packages published less than 24 hours ago) which is a specific, cheap control rather than a general recommendation.

We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services.

They went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026.

Wiz Research 2026-08-06
annual-report08 Aug 05:22Zsingle-sourceOpen finding →
Sources: Wiz Research

Earlier coverage (13)

2026-07-14NOTABLENATOB2Cisco Talos maps the full taxonomy of Python-package build-time and import-time code execution ("The Serpent's Tongue")Cisco Talos published a lifecycle survey of code-execution paths in Python packaging (from setup.py running at install time to persistent .pth files, site-hook modules and PYTHONPATH hijacking that fire on every subsequent Python invocation) tying the taxonomy to real TeamPCP supply-chain compromises (litellm, lightning). It is a reference for supply-chain defenders and a concrete hunt surface for teams running Python build/CI pipelines.2026-06-09HIGHupdatedTeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivativeTeamPCP open-sources its Mini Shai-Hulud supply-chain framework on GitHub, spawning a new "Phantom Gyp" derivative and underscoring that valid SLSA provenance does not survive a subverted build environment (SANS ISC, 2026-06-08).2026-06-12NOTABLEnpm v12 will disable install scripts by default, audit CI/CD pipelines before JulyGitHub announced that npm v12 (expected July 2026) disables dependency lifecycle scripts (preinstall/install/postinstall, including implicit node-gyp builds) by default, requires npm approve-scripts for explicit opt-in, and blocks Git/remote-URL dependencies without --allow-git/--allow-remote (GitHub …2026-06-02HIGHupdated"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse"Miasma" supply-chain worm compromised 32 @redhat-cloud-services npm packages via a hijacked maintainer GitHub account and OIDC trusted-publishing abuse, adding new GCP and Azure cloud-identity collectors (Wiz, 2026-06-01).2026-05-28HIGHexploitedNx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entriesCISA added three supply-chain CVEs to KEV on 2026-05-27, the Nx Console / TanStack / DAEMON Tools cascade. The Nx Console v18.95.0 VS Code extension compromise (CVE-2026-48027) ultimately traces to a TanStack Router npm supply-chain bug (CVE-2026-45321) that exfiltrated a contributor's GitHub CLI OAuth token; GitHub later confirmed that roughly 3,800 internal repositories and Grafana Labs were also breached. Separately, CVE-2026-8398 covers a six-week trojanisation of signed DAEMON Tools Lite builds 12.5.0.2421–12.5.0.2434 from the official vendor build pipeline.2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strandA Packagist (PHP/Composer) supply-chain wave hit the Laravel-Lang ecosystem, 700+ version tags rewritten to point at attacker forks, an autoload.files backdoor that executes on every request, and a separate 8-package package.json postinstall strand dropping a Linux implant. Full mechanics in today's deep dive (Socket, 2026-05-23).2026-05-24NOTABLEnpm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm wavesUPDATE (supply-chain worm wave, originally covered 2026-05-23): GitHub announced on 2026-05-22 that npm staged publishing is now Generally Available; a maintainer must run npm stage publish (npm CLI 11.15.0+), which uploads the version to a consumer-invisible staging queue, then pass a separate 2FA …2026-05-21HIGHVerizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 yearsVerizon 2026 DBIR (today's deep dive): vulnerability exploitation overtakes credentials as the leading breach initial-access vector for the first time in the report's 19-year history, 31 % per Verizon's press release (Verizon, 2026-05-19) vs 13 % credentials per Help Net Security's reading of the full DBIR (Help Net Security, 2026-05-20); only 26 % of CISA KEV entries fully remediated (down from 38 %); supply-chain breaches +60 % YoY.2026-05-15NOTABLEDatadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source codeUPDATE (2026-05-13, follows TeamPCP coverage 2026-05-13): Datadog Security Labs published an analysis of the TeamPCP "Shai-Hulud" offensive worm source code on 2026-05-13, after the complete framework was briefly accessible as a public GitHub repository on 2026-05-12 before the account was removed (Datadog …2026-05-15NOTABLESophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectorsSophos published its State of Identity Security 2026 survey on 2026-05-14, drawing on responses from IT and cybersecurity leaders across 17 countries (Help Net Security, 2026-05-14).2026-05-13NOTABLEMini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft ChainBackground. Mini Shai-Hulud (the TeamPCP self-propagating npm worm) first surfaced in coverage on 2026-05-10 as a SAP CAP-package compromise.2026-05-12HIGHGTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented MalwareGoogle Threat Intelligence Group confirms first AI-generated zero-day exploit observed in the wild. A criminal campaign used an LLM-generated Python exploit (semantic-logic 2FA bypass in an unnamed widely-deployed open-source sysadmin tool) before responsible disclosure cut it short (Google Cloud Threat Intelligence, 2026-05-11). Same report documents AI-augmented malware families (CANFAIL, LONGSTREAM, PROMPTFLUX, HONESTCUE) and state-actor Gemini abuse, full treatment in § 5 Deep Dive.2026-05-12HIGHexploitedTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runnerTeamPCP (UNC6780) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months. Malicious plugin build 2026.5.09 published to the Jenkins Marketplace on 2026-05-09–10 deploys SANDCLOCK to exfiltrate every CI secret reachable from the runner (cloud keys, container-registry credentials, Checkmarx API tokens) (The Hacker News, 2026-05-11; Checkmarx, Ongoing Security Updates, last update 2026-05-09). Treat any pipeline that auto-updated in the window as a full secrets-compromise event.

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats6
  • Deep dive5
  • Research4
  • Vulns1

Source distribution

  • attack.mitre.org11 (16%)
  • thehackernews.com8 (12%)
  • socket.dev5 (7%)
  • helpnetsecurity.com4 (6%)
  • securityweek.com3 (4%)
  • wiz.io3 (4%)
  • aikido.dev2 (3%)
  • bleepingcomputer.com2 (3%)
  • other31 (45%)
All cited sources (69)