govinfosecurity.com
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-08-28.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-08-28 2026 | Two Australian Men Charged in TeamPCP Supply Chain AttacksSupply Chain | Writeup detailing the arrests of two Australian men, Ruben Ian Thomson and Louis Michael Gaebler, for their alleged leadership in the TeamPCP cybercrime group. This group conducted extensive software supply chain attacks, compromising over 1,000 organizations by injecting credential-stealing malware into open-source software like Aqua Security's Trivy and LiteLLM. The attacks, which exposed over 500,000 credentials and exfiltrated significant data, also involved the Mini Shai-Hulud worm and targeted platforms including npm, PyPI, and GitHub, impacting vendors like TanStack, Mistral AI, UiPath, and OpenSearch. |
| 2026-08-12 2026 | How Postman Embeds Wiz Risk Data Into Dev WorkflowsAPI Sec | Library for embedding Wiz risk data into developer workflows, specifically Postman's API Catalog. This integration surfaces known exploitable vulnerabilities, secrets, and misconfigurations within developer environments, offering one-click remediation commands. The approach enhances security KPIs by allowing developers to quickly address risks directly within their existing tools, representing a genuine shift-left security practice. |
| 2026-05-25 2026 | Automated 'Megalodon' Campaign Spreads GitHub Repo BackdoorsSupply Chain | Library of GitHub Actions workflows that spread the 'Megalodon' campaign, targeting over 5,000 repositories. This automated attack injects base64-encoded bash payloads via forged author identities, stealing CI/CD secrets, cloud credentials, and SSH keys. Variants include 'SysDiag' and 'Optimize-Build,' with affected repositories needing commit reverts, secret rotation, and audit log reviews, particularly for OIDC federation. |
| 2026-05-13 2026 | Mass Supply-Chain Attack Slams npm and PyPi Hits Mistral AISupply Chain | Library for detecting and defending against supply-chain attacks, exemplified by the Mini Shai-Hulud worm that targeted npm and PyPI packages, including those from Mistral AI and TanStack. This malware family, known for credential stealing and wiper capabilities, spreads autonomously by compromising publish tokens and includes country-aware logic. Defense strategies include implementing code cooldown periods before package integration and enforcing multifactor authentication across developer accounts. |
| 2026-04-24 2026 | Flurry of Supply-Chain Software Library AttacksSupply Chain | Library attacks targeting npm and PyPI repositories have surged, compromising open-source projects like LiteLLM, Axios, Xinference, Namastex.ai, Checkmarx KICS, and Bitwarden CLI. Attackers inject data-stealing malware and worms, such as Shai-Hulud, into popular packages, which are then automatically merged into downstream projects via CI/CD pipelines. These compromises aim to steal developer credentials, cloud secrets, and spread laterally to other repositories, highlighting the fragility of software supply chains. |