appsec.fyi · Sources

govinfosecurity.com

5 curated AppSec resources from govinfosecurity.com across 2 topics on appsec.fyi.

govinfosecurity.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-08-28.

Date Added Resource Excerpt
2026-08-28 2026Two Australian Men Charged in TeamPCP Supply Chain AttacksSupply ChainWriteup detailing the arrests of two Australian men, Ruben Ian Thomson and Louis Michael Gaebler, for their alleged leadership in the TeamPCP cybercrime group. This group conducted extensive software supply chain attacks, compromising over 1,000 organizations by injecting credential-stealing malware into open-source software like Aqua Security's Trivy and LiteLLM. The attacks, which exposed over 500,000 credentials and exfiltrated significant data, also involved the Mini Shai-Hulud worm and targeted platforms including npm, PyPI, and GitHub, impacting vendors like TanStack, Mistral AI, UiPath, and OpenSearch.
2026-08-12 2026How Postman Embeds Wiz Risk Data Into Dev WorkflowsAPI SecLibrary for embedding Wiz risk data into developer workflows, specifically Postman's API Catalog. This integration surfaces known exploitable vulnerabilities, secrets, and misconfigurations within developer environments, offering one-click remediation commands. The approach enhances security KPIs by allowing developers to quickly address risks directly within their existing tools, representing a genuine shift-left security practice.
2026-05-25 2026Automated 'Megalodon' Campaign Spreads GitHub Repo BackdoorsSupply ChainLibrary of GitHub Actions workflows that spread the 'Megalodon' campaign, targeting over 5,000 repositories. This automated attack injects base64-encoded bash payloads via forged author identities, stealing CI/CD secrets, cloud credentials, and SSH keys. Variants include 'SysDiag' and 'Optimize-Build,' with affected repositories needing commit reverts, secret rotation, and audit log reviews, particularly for OIDC federation.
2026-05-13 2026Mass Supply-Chain Attack Slams npm and PyPi Hits Mistral AISupply ChainLibrary for detecting and defending against supply-chain attacks, exemplified by the Mini Shai-Hulud worm that targeted npm and PyPI packages, including those from Mistral AI and TanStack. This malware family, known for credential stealing and wiper capabilities, spreads autonomously by compromising publish tokens and includes country-aware logic. Defense strategies include implementing code cooldown periods before package integration and enforcing multifactor authentication across developer accounts.
2026-04-24 2026Flurry of Supply-Chain Software Library AttacksSupply ChainLibrary attacks targeting npm and PyPI repositories have surged, compromising open-source projects like LiteLLM, Axios, Xinference, Namastex.ai, Checkmarx KICS, and Bitwarden CLI. Attackers inject data-stealing malware and worms, such as Shai-Hulud, into popular packages, which are then automatically merged into downstream projects via CI/CD pipelines. These compromises aim to steal developer credentials, cloud secrets, and spread laterally to other repositories, highlighting the fragility of software supply chains.