appsec.fyi

Supply Chain Security Resources

Post Share

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Supply Chain Security

Software supply chain security addresses threats that target the dependencies, build systems, and distribution channels that modern applications rely on. High-profile incidents like SolarWinds, Log4Shell, and the xz backdoor demonstrated that attackers increasingly target upstream components rather than applications directly. Supply chain attacks include dependency confusion (substituting malicious packages with names matching internal packages), typosquatting in package registries, compromised maintainer accounts, malicious code injected into build pipelines, and trojanized development tools. Defenses include software bills of materials (SBOMs), dependency pinning and lock files, signature verification, provenance attestation (SLSA framework), regular dependency auditing with tools like Dependabot, Snyk, or Socket, and careful evaluation of new dependencies before adoption.

You audit your code and ship everyone else's

A typical application is a small amount of first-party code on top of a very large dependency tree, built by a pipeline with broad credentials and deployed through infrastructure that trusts its own artifacts. Reviewing the first-party code carefully while treating everything underneath as given is the normal state of affairs, and it is the gap this category is about.

The attack surface splits usefully into three. Package ecosystems: typosquatted names, dependency confusion where a public registry answers for an internal package name, compromised or transferred maintainer accounts, and install-time script execution that runs before anyone has read anything. Build systems: CI configuration is code with credentials, and a pull request that triggers a privileged workflow has historically been enough to extract them; caches and artifact stores are tempting because poisoning one affects every consumer downstream. Distribution: signing key compromise, update channel manipulation, and container base images that nobody has rebuilt.

What makes these attractive is amplification. Compromising one widely-used package reaches every application that installs it, which is a return no application-level bug offers. The incidents that shaped current practice — SolarWinds, Codecov, event-stream, the recurring npm and PyPI campaigns — are worth reading in full rather than in summary, because the interesting detail is usually how long the access went unnoticed and what specifically failed to detect it.

On defence, the honest position is that the ecosystem is still building the primitives. SBOMs give you an inventory, which is necessary and not sufficient. Pinning with hash verification prevents silent substitution. Reproducible builds and artifact signing with frameworks like SLSA and Sigstore address provenance. Restricting install-time scripts and isolating CI credentials are unglamorous and effective. Vendoring trades update friction for control.

The practical starting point is inventory: most organizations cannot currently answer which applications include a given package version, and everything else depends on being able to.

Start here: the Supply Chain learning pathAn ordered route through this library — orientation, then methodology, then research. Read the Supply Chain guideA long-form, source-cited deep dive synthesized from every resource below. The comprehensive Supply Chain guide on chs.usA hand-written, in-depth practitioner guide — attacks, testing, and prevention.
Date Added Link Excerpt
2026-10-09 NEW 2026[tl;dr sec] #349 - Vulns & Exploits in the AI Era, Package Manager Sandboxing, Testing AI Sandboxes news AIThis summary covers emerging vulnerabilities and exploits within the AI landscape, as observed by the Google Threat Intelligence Group. It also delves into how package managers implement sandboxing techniques and presents findings from tests conducted on the sandboxing environments of Vercel and Perplexity. The focus is on understanding security challenges and solutions in the context of AI development and deployment. → tldrsec.com
2026-10-08 NEW 2026Evolution of Web3 in Cloud Supply Chain Attacks intermediate 8 min readAnalysis of Web3 in Cloud Supply Chain Attacks details how threat actors leverage decentralized blockchain architectures for command-and-control (C2) infrastructure, moving beyond static endpoints. Campaigns like ChainDrop and PolinRider demonstrate the exploitation of open-source dependencies to harvest cloud identity tokens and secrets. These attacks, attributed to state-sponsored actors like Alluring Pisces, utilize techniques such as EtherHiding and TxDataHiding across networks like TRON, Aptos, and Binance Smart Chain to dynamically update botnets and maintain persistence, bypassing traditional security controls. → unit42.paloaltonetworks.com
2026-10-02 NEW 2026Your SBOM Is Fan Fiction news 8 min readTool for runtime Software Bill of Materials generation; queries `/proc` for process dependencies and maps, then correlates with package data and CVE advisories using `yeet.graph.query` and `yeetkit` for enriched security insights on live systems.
2026-10-02 NEW 2026Public Secrets Monitoring: Find a Credential Leak Beyond Your Borders news 10 min read SecretsAnalysis of GitGuardian's Public Monitoring Agents enhances credential leak detection by identifying hardcoded secrets in public GitHub commits, a problem amplified by developer personal repositories and incidents like the CISA leak. This updated tool categorizes public incidents with new verdicts ("Related," "Uncertain," "Unrelated") to prioritize company-relevant exposures, streamlining investigations by organizing the incident queue around relevance and providing reasoning for each verdict. → blog.gitguardian.com
2026-10-01 2026Securing the Kubernetes Supply Chain: Introducing WizOS Helm Charts intermediate 8 min readLibrary for securing Kubernetes supply chains, WizOS Helm Charts offers hardened, signed, and CVE-scanned packages. It addresses risks in community charts, such as unmaintained dependencies and vulnerable CI/CD workflows, by rebuilding and signing all charts within Wiz's own secure pipeline. This ensures that deployed software is free from upstream vulnerabilities and misconfigurations, with scheduled patching and verified provenance for compliance. → wiz.io
2026-09-30 2026The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub intermediate 5 min read SecretsLibrary for investigating multi-platform data exfiltration across AWS and GitHub, showcasing autonomous SOC investigation by uncovering compromised credentials, stolen source code, and custom data exfiltration tooling. It traces attack chains involving suspicious VPN activity, unusual API calls, and known offensive tools, correlating signals across platforms to identify staged Python scripts like `mssql_table_export.py`, `pg_table_export.py`, and `billing_export2.py` used to extract sensitive data. The investigation also highlights initial access via GitHub, where private repositories were cloned using a compromised token from a Zenlayer IP. → wiz.io
2026-09-27 2026AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks intermediate 49 min read AIAnalysis of 15 default AI Helm charts reveals significant security gaps. Ten of fourteen charts omit native API authentication, and all six tested live accepted unauthenticated requests. Ten charts fail to enforce non-root execution, with seven combining this with unauthenticated access. All charts mount default ServiceAccount tokens, 14 lack default NetworkPolicies, and 4 grant cluster-wide Secret read access. The LiteLLM chart specifically embeds plain-text database credentials in environment variables. Operators must configure authentication, network policies, and non-root execution before production deployment.
2026-09-25 2026Lunex Unmasked: A New Information Stealer Deployed Through BYOVD intermediate 17 min read MobileLibrary detailing the Lunex information stealer, a four-stage attack chain targeting Ukrainian users. This analysis uncovers the loader's Bring Your Own Vulnerable Driver (BYOVD) technique to disable kernel-level security, the use of obfuscated strings, and privilege escalation via auto-elevating COM objects. Lunex steals browser credentials, cryptocurrency wallets, and establishes persistent access, with its command-and-control infrastructure traced to a CIS-aligned, financially motivated threat actor.
2026-09-25 2026[tl;dr sec] #347 - AI Agents Hacking Companies for $25, Threat Hunter's Guide to GitHub, Finding Gadgets Like it’s 2026 news 13 min read AILibrary for analyzing supply chain toolchains and Git repository usage. It detects project tools, maps them to CWE/OWASP categories, and identifies dangerous functions. It also analyzes dependency history over time, scans against OSV, checks licenses, and flags potential supply chain tampering. Additionally, this entry includes techniques for investigating GitHub PAT compromise using a six-step approach and a threat hunting guide for GitHub audit logs to detect compromised accounts, source code exfiltration, and pivoting. → tldrsec.com
2026-09-24 2026Send GitLab an email, push to main intermediate 8 min read RCELibrary for identifying vulnerabilities in GitLab's incoming email feature, where a leaked project email address grants attackers account-wide access. This allows for pushing code to protected branches, running CI/CD jobs, and exfiltrating secrets, bypassing IP restrictions that would otherwise block access. The embedded token acts as a powerful Personal Access Token, and its inherent design risks significant compromise without a mechanism for selective revocation or sender verification. → aikido.dev
2026-09-23 2026Graphalgo campaign spreads to Terraform providers and Go Modules news 7 min readWriteup detailing the Graphalgo campaign's expansion into Terraform providers and Go Modules, marking the first observed malware distribution via Terraform. The analysis highlights compromised packages like gocommunity-io/dockerd and kreuzwenker/docker, and Go Modules gocommunity.io/orderedbtree and gogets.dev/btreex. It describes the malware's sophisticated command-and-control mechanisms utilizing Slack channels and an Ethereum smart contract on Arbitrum Sepolia for encrypted communication and code execution, including a second-stage RAT. → aikido.dev
2026-09-18 2026What a Supply Chain Attack Is Really After: Your Credentials beginner 5 min read SecretsEbook detailing credential-harvesting software supply chain attacks, such as Shai-Hulud 2.0 and Trivy compromise, focusing on how malicious packages target developer environments and CI/CD pipelines to steal GitHub tokens, package publishing credentials, SSH keys, and cloud credentials, enabling attackers to propagate and gain further access. → blog.gitguardian.com
2026-09-15 2026Dependabot vs Renovate beginner 12 min readLibrary comparing Dependabot and Renovate, two dependency management tools. Dependabot excels with zero-setup simplicity on GitHub, while Renovate offers deeper configuration and multi-platform support for monorepos and complex setups. Both tools, however, are limited by their reflexive version bumping, which risks breaking changes and introducing new vulnerabilities. The article suggests that true dependency security requires reachability analysis and integration with SAST and secrets detection, like that offered by Aikido Security. → aikido.dev
2026-09-11 2026[tl;dr sec] #345 - Bug Rumors → Exploits, Version Control DFIR, Agentic Worms news 8 min read AILibrary for securing applications, this catalog entry highlights research and tools addressing evolving threats. It includes an analysis of AI models' effectiveness in code review, demonstrating how AI can generate exploits from bug descriptions, and a cheatsheet for Digital Forensics and Incident Response on version control systems like GitHub and GitLab. The entry also touches on the challenge of false positives in detection tools and the implications of agentic worms. → tldrsec.com
2026-09-09 2026Compromised Flutter package on pub.dev contains XCSSET malware news 7 min read PythonLibrary containing a malicious variant of XCSSET malware detected in the `universal_file_viewer` Flutter package on pub.dev. This malware infects macOS systems by injecting build hooks into Android Gradle projects, Xcode projects, and Git repositories, and exfiltrates sensitive data from browsers, desktop applications, and clipboard. The XCSSET worm spreads via build process infection and can persist by replacing the Launchpad Dock tile. → aikido.dev
2026-09-06 2026HOL Guard intermediate AI SecretsLocal-first runtime security for AI coding agents and MCP tooling. It sits between an agent and the tools it wants to run so developers can approve or deny risky shell commands, secret reads, prompt-injection-driven actions, malicious packages, and MCP changes before execution.
2026-09-05 2026Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you news 8 min readTool for detecting compromise of Coder's registry modules. This tool checks for unauthorized IP addresses, tampered modules serving `dlp.sh` or `dlp-docker.sh`, and exfiltration to `coder-infra.com`. It addresses the GHSA-vx42-ghc9-gw65 vulnerability by scanning Coder deployments, provisioners, images, and egress logs for indicators of compromise, recommending credential rotation and patching.
2026-09-04 2026CrowdStrike introduces real-time supply chain attack protection newsLibrary for real-time supply chain attack protection, intercepting malicious software packages at the endpoint before embedded scripts execute. It leverages AI coding agent acceleration of open-source package adoption to combat adversaries poisoning software components, functioning as a final checkpoint by examining package-manner transactions at the command line. This solution extends existing endpoint protection without new agents or proxies, offering granular controls and automatic remediation of compromised packages. → msspalert.com
2026-09-04 2026How Developers Prevent Production Risk at the Source beginner 5 min readLibrary for integrating security checks directly into the software development lifecycle, focusing on early detection and remediation of vulnerabilities. It supports security at various stages, including developer sessions with AI agents, commit gates, pull request analysis, repository scanning, and CI/CD pipeline build gates. The library aims to reduce production risk and operational costs by addressing security flaws at the code level, preventing issues like CVEs in base images (e.g., node:20-slim) and hardcoded secrets from reaching production. → wiz.io
2026-09-04 2026CrowdStrike Extends Its Endpoint Advantage to Secure the Software Supply Chain news 2 min readLibrary introducing Real-Time Supply Chain Attack Protection, a Falcon platform innovation that blocks malicious open-source packages at the endpoint before execution. This capability counters threats like DPRK-nexus adversary STARDUST CHOLLIMA poisoning AI framework packages and eCrime actor ALTERED SPIDER compromising software dependencies. It intercepts at the command line, preventing embedded scripts from running and securing the broader enterprise attack surface widened by AI agents.
2026-09-04 2026CrowdStrike Introduces Real-Time Supply Chain Attack Protection on Falcon Platform news 1 min readLibrary protecting against real-time supply chain attacks on the Falcon platform intercepts malicious open-source packages like those from npm and PyPI at the endpoint before their embedded code executes. This innovation uses the existing Falcon sensor to block compromised packages across Windows, macOS, and Linux, even as they are installed via package managers like `npm install` or `pip install`. It provides granular controls, global package inventory, and automatic remediation through Charlotte Agentic SOAR, making the endpoint the control point for software supply chain security.
2026-09-04 2026Malware in Rust Crates With 245M Downloads North Korea Behind the crates.io Supply Chain Attack newsRust's package manager, crates.io, was targeted in a supply chain attack attributed to North Korea. Malicious code was discovered within several popular Rust crates, impacting projects with a combined total of 245 million downloads. This incident highlights significant security vulnerabilities in the open-source software ecosystem and the persistent threats posed by state-sponsored actors. Further details on the specific malware and its impact are available in the linked article.
2026-09-03 2026CrowdStrike Extends Endpoint Security to Stop Supply Chain Attacks news 5 min readLibrary extending endpoint security to halt software supply chain attacks, as detailed in the CrowdStrike 2026 Threat Hunting Report. This capability natively integrated into the Falcon sensor detects and blocks malicious open-source packages like those seen in STARDUST CHOLLIMA and ALTERED SPIDER campaigns before execution, while also providing a global inventory of installed packages across all endpoints, including those used by AI agentic applications. It offers proactive policy controls, such as minimum package age requirements and restrictions on publicly available packages, to govern code ingestion and mitigate risks from newly released or untrusted dependencies.
2026-09-03 2026Hackers Are Exploiting a Critical Flaw in JFrog's Artifactory Tool news 4 min readLibrary exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, allows unauthenticated attackers network access to gain administrator privileges. Exploitation began days after JFrog's August 28, 2026 disclosure. This vulnerability, affecting self-hosted deployments with a CVSS score of 9.8, poses a significant supply-chain risk by enabling tampering with build artifacts. WatchTowr observed early exploitation, with attackers minting administrator tokens and enumerating users and access topologies. Patching immediately is crucial for vulnerable instances. → startupfortune.com
2026-09-03 2026CrowdStrike Launches Real-Time Supply Chain Attack Protection news 3 min readLibrary that blocks malicious open-source packages at the endpoint in real time, before embedded code executes. It intercepts package manager transactions across npm and PyPI on Windows, macOS, and Linux, preventing compromises like those seen from STARDUST CHOLLIMA poisoning AI framework packages or ALTERED SPIDER compromising software dependencies. The solution extends protection to all endpoints, offers granular controls, and integrates automated investigation and response capabilities.
2026-09-03 2026OWASP Top 10 CI/CD Security Risks Explained: Why Credential Hygiene Decides the Outcome beginner 11 min read SecretsLibrary summarizing the OWASP Top 10 CI/CD Security Risks, emphasizing how exposed or overprivileged credentials (CICD-SEC-6) amplify other vulnerabilities. It details risks like dependency chain abuse (CICD-SEC-3), poisoned pipeline execution (CICD-SEC-4), and insecure system configurations (CICD-SEC-7). The entry highlights the acceleration of attacks since 2025, mentioning worms like Shai-Hulud and ChainDrop, and notes that 59% of compromised machines in a recent wave were CI/CD runners. → blog.gitguardian.com
2026-09-03 2026CrowdStrike Extends Its Endpoint Advantage to Secure the Software Supply Chain newsCrowdStrike is extending its endpoint security expertise to protect the software supply chain. This expansion aims to prevent attackers from compromising development pipelines and injecting malicious code into legitimate software. By leveraging its existing endpoint detection and response (EDR) capabilities, CrowdStrike will offer new tools and services to identify vulnerabilities and threats throughout the software development lifecycle. This initiative addresses the growing risks associated with increasingly complex and interconnected software development processes.
2026-09-02 2026CrowdStrike Moves to Secure Software Supply Chains at the Endpoint news 3 min readLibrary for real-time supply chain attack protection that blocks malicious open-source packages at the endpoint, safeguarding both human developers and AI coding agents on Windows, macOS, and Linux. It intercepts package manager transactions before embedded code executes, providing DevSecOps teams visibility into compromised package installations and enabling automated remediation workflows, even against threats like STARDUST CHOLLIMA and eCrime actor ALTERED SPIDER. → devops.com
2026-09-02 2026The dark figure of supply chain detection beginner 7 min readLibrary for application security detection engineering that highlights the "dark figure of crime" in supply chain attacks. It argues against relying solely on string-based or Indicator of Compromise (IOC) rules, which only catch previously identified threats. Instead, it advocates for behavioral analysis, mapping normal package behavior to identify deviations. This approach, exemplified by the detection of a malicious Keyv package on August 4th, 2026, allows for the identification of sophisticated attacks that evade signature-based methods by focusing on what a package *does* rather than what it *is*. → aikido.dev
2026-09-01 2026Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure news 2 min readWriteup of CVE-2026-82329, a critical authentication bypass in JFrog Artifactory allowing unauthenticated attackers network access to mint administrator tokens. This flaw, affecting specific Artifactory versions, resides in JFrog Access and enables attackers to forge credentials by abusing a 'phantom' join key. Threat actors have actively exploited this vulnerability, potentially leading to build pipeline tampering, lateral movement, and malicious code distribution downstream to customers. Organizations are advised to immediately patch internet-exposed systems and review logs for suspicious activity. → thehackernews.com
2026-09-01 2026Hugging Face Security Incident: A New Class of Threat Is Here news 5 min readLibrary for managing AI-enabled software supply chain security, building on lessons from the Hugging Face incident. It provides proactive dependency intelligence, real-time awareness of threats like malicious datasets and autonomous agent systems, and visibility and governance for AI artifacts alongside traditional components. Automated response capabilities, such as identifying safer upgrade paths, help teams quickly remediate identified risks and maintain pace with AI-accelerated development. → sonatype.com
2026-09-01 2026Our response to the TanStack npm supply chain attack newsTanStack is responding to a supply chain attack targeting its npm packages. The attack involved a malicious actor gaining access to an npm account and publishing compromised versions of TanStack's libraries. This allowed the attacker to potentially inject malicious code into projects using these packages. TanStack has taken immediate action to mitigate the threat, including revoking compromised credentials and working to restore legitimate package versions. They are urging users to update to secure versions and implement security best practices. No payout amount was mentioned.
2026-08-31 2026When AI Models Become the Supply Chain Attack advancedLibrary for securing AI supply chains against threats like model poisoning and compromised updates. It recommends implementing a Model Gateway for prompt and response inspection, centralizing model access for logging and policy enforcement, and treating model updates like software releases with versioning and rollback plans. The library also advises monitoring prompt traffic for anomalies and controlling downstream actions from model outputs to prevent manipulation and real-world harm.
2026-08-31 2026Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain intermediate 5 min read SecretsLibrary that correlates developer identities with their personal public repositories, validating exposed secrets for exploitability. It addresses blind spots in traditional AppSec programs by identifying, validating, and driving fixes for secrets leaked from corporate code into personal accounts, a problem accelerated by AI development and impacting critical infrastructure access across Forbes AI 50 and other organizations. → wiz.io
2026-08-30 2026Operation RepoGhost: Exposing a Russian-Linked Malware Campaign Hiding in GitHub’s Open-Source… newsOperation RepoGhost is a recently discovered malware campaign, active since November 2025, orchestrated by Russian-linked threat actors. Researchers have identified a network of fake GitHub repositories designed to impersonate legitimate IT software and projects. This tactic aims to lure unsuspecting developers into downloading malicious code disguised as legitimate open-source tools. The campaign leverages the trust and prevalence of GitHub to distribute malware, posing a significant threat to the open-source ecosystem. The specific payout amounts for bug bounties related to this campaign were not disclosed. → infosecwriteups.com
2026-08-29 2026Securing Docker images intermediate 14 min readLibrary for hardening Docker images, focusing on vulnerability management by shrinking the attack surface and implementing correct permissions. It addresses risks from base images, like CVE-2023-4911 in glibc, and advocates for minimal bases, multi-stage builds, and removing unused packages. The library also covers essential security practices such as running as a non-root user, utilizing read-only filesystems, dropping unnecessary Linux capabilities, and properly managing secrets to prevent them from being baked into image layers. → aikido.dev
2026-08-28 2026Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI and thousands more news 2 min readWriteup on TeamPCP's global supply chain crime spree, detailing the activities of the "Shai-Hulud hackers" who compromised open source software on platforms like GitHub and NPM. The group created malicious versions of legitimate packages to steal data and extort ransoms, impacting over 1000 organizations worldwide. Notable targets included vulnerability scanner Trivy, AI gateway LiteLLM, Mercor, and even OpenAI and the European Commission's cloud infrastructure.
2026-08-28 2026Perth arrests reveal the supply chain blind spot in Australian cyber cover news 5 min readLibrary addressing software supply chain vulnerabilities; this resource details an alleged TeamPCP attack orchestrated by two men in Perth, which compromised over 1,000 organizations globally, exfiltrated 300GB of data, and stole over 500,000 credentials. The incident highlights systemic risks to Australian insurance brokers, with potential policy gaps concerning third-party providers and widespread events. Investigations by the AFP, WAPF, and FBI led to charges including unauthorized data modification and dealing with proceeds of crime, underscoring the professionalization of cybercrime syndicates and the ASD's identification of IT supply chains as a structural vulnerability.
2026-08-28 2026Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps intermediate 7 min readCheatsheet for Version Control DFIR, covering GitHub, GitLab, Bitbucket, and Azure DevOps, provides essential information for threat hunting and incident response in these systems. It details available log sources, noting retention limitations for events like Git operations and API requests, and offers a pre-incident readiness checklist focusing on enabling complete metadata and extending data retention. The resource also includes an attack detection and forensic matrix mapping VCS audit events to MITRE ATT&CK tactics, helping security teams translate adversary behaviors into actionable queries across different platforms for identifying compromised tokens, mass repository cloning, and log deletion. → wiz.io
2026-08-28 2026Two Australian Men Charged in TeamPCP Supply Chain Attacks news 4 min readWriteup detailing the arrests of two Australian men, Ruben Ian Thomson and Louis Michael Gaebler, for their alleged leadership in the TeamPCP cybercrime group. This group conducted extensive software supply chain attacks, compromising over 1,000 organizations by injecting credential-stealing malware into open-source software like Aqua Security's Trivy and LiteLLM. The attacks, which exposed over 500,000 credentials and exfiltrated significant data, also involved the Mini Shai-Hulud worm and targeted platforms including npm, PyPI, and GitHub, impacting vendors like TanStack, Mistral AI, UiPath, and OpenSearch. → govinfosecurity.com
2026-08-27 2026Two alleged TeamPCP hackers arrested over global supply chain attacks news 2 min readArrests of alleged TeamPCP hackers in Australia detail a global supply chain attack campaign. These individuals are accused of planting malicious code into open-source software, impacting over a thousand organizations worldwide. Techniques employed included a self-spreading worm, Mini Shai-Hulud, used to steal credentials and authentication tokens, with impacts noted on platforms like GitHub and Red Hat. The operation reportedly resulted in the theft of over 500,000 credentials and 300 gigabytes of data, with remediation costs estimated in the hundreds of millions. → helpnetsecurity.com
2026-08-27 2026Two Arrests One Supply-Chain Attack and a Lot of Stolen Credentials news 4 min readWriteup detailing the arrest of two individuals for their alleged involvement in TeamPCP's global supply-chain attack campaign. This operation targeted open-source repositories, including PyPI and NPM, injecting malicious code into popular tools like Trivy, KICS, LiteLLM, and the Telnyx Python SDK. The campaign reportedly compromised over 1,000 organizations, leading to the theft of over 500,000 credentials and 300 gigabytes of data, using malware families such as CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma. → securityaffairs.com
2026-08-27 2026Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos news 2 min readWriteup of the TeamPCP supply-chain attack campaign, detailing the arrests of two alleged members, Ruben Ian Thomson and Louis Michael Gaebler, by Australian authorities. The group compromised over 1,000 organizations through malicious code insertion into open-source software, including attacks against Trivy and libraries like TanStack, UiPath, and MistralAI. The campaign exposed hundreds of thousands of credentials and resulted in significant global cleanup costs, highlighting the ongoing threat of software supply-chain attacks. → cyberscoop.com
2026-08-27 2026TeamPCP suspects arrested in Australia cybercrime case newsAustralian authorities have arrested suspects linked to the cybercrime group TeamPCP. The arrests are part of a broader international operation targeting online fraud and malicious software. While the content doesn't specify a bounty payout, the arrests indicate a significant development in combating cyber threats. The investigation aims to dismantle the group's operations and prosecute those involved in their illegal activities. → cybernews.com
2026-08-27 2026Australia arrests alleged TeamPCP hackers behind supply-chain attacks news 2 min readWriteup on the TeamPCP supply-chain attacks, detailing their targeting of open-source software and developer platforms to steal credentials and source code. Investigations by Flare and Brian Krebs, alongside Australian Federal Police and FBI efforts, linked alleged TeamPCP members to their real-world identities, leading to arrests and charges for computer offenses and data modification. These attacks, impacting Trivy, LiteLLM, and SAP packages, potentially compromised over a thousand organizations globally. → bleepingcomputer.com
2026-08-27 2026Two WA men charged after AFP-FBI-WAPF probe into alleged open-source supply-chain attack news 4 min readTool that aids in discovering supply-chain attack vectors; this catalog entry summarizes an investigation where the TeamPCP cybercrime syndicate allegedly inserted malicious code into open-source software, compromising over 1,000 organizations globally. The attack, enabled by compromising trusted components, led to the theft of hundreds of thousands of credentials and significant data exfiltration, resulting in arrests in Western Australia and highlighting the critical need for software supply-chain integrity.
2026-08-27 2026Shai-Hulud was the best thing to happen to supply chain security news 9 min readLibrary for securing npm packages, Shai-Hulud, highlights the impact of sophisticated attacks like S1ngularity, Shai-Hulud 2.0, and Miasma on adoption of Trusted Publishing. These campaigns, exploiting compromised CI pipelines and OIDC endpoint abuse, prompted maintainers to adopt the OIDC-based credential system, replacing long-lived tokens with short-lived ones to mitigate risks from token theft and malicious code execution. → aikido.dev
2026-08-27 2026Software supply chain security requires decisions rather than defaults intermediate 5 min readLibrary that backports security fixes, like those for xz-utils and lodash, to existing software versions. This approach avoids the risks associated with forced upgrades, such as introducing new vulnerabilities or breaking builds. The library emphasizes informed decision-making over default upgrade behaviors, allowing teams to maintain stable, trusted software baselines. It enables continuous management of software supply chains through proactive evaluation and controlled changes at the point of entry. → aikido.dev
2026-08-26 2026How Utility Warehouse Secured Its Software Supply Chain Across CI/CD NPM and Developer Machines with StepSecurity intermediate 4 min readLibrary for securing software supply chains, StepSecurity, enabled Utility Warehouse to gain visibility into CI/CD pipeline behavior, NPM dependency risk, and developer toolchains like Claude Code and GitHub Copilot. It proactively blocked a compromised NPM package introduced via refactoring and detected anomalous outbound network activity during CI/CD runs, preventing potential breaches. The solution integrates seamlessly without disrupting developer workflows, offering peace of mind against escalating software supply chain threats. → stepsecurity.io
2026-08-26 2026Active Exploitation Alert: Critical Supply Chain Attack via 14 Trojanized npm Packages Drops RedC2 4.0 AI-Assisted Linux Backdoor news 4 min readLibrary for detecting and analyzing a critical supply chain attack involving 14 trojanized npm packages that deploy the RedC2 4.0 AI-assisted Linux backdoor. The attack targets developer environments and Linux servers, exploiting the trust in open-source dependencies to execute malicious payloads and establish persistence. RedC2 4.0 offers interactive shell access, system discovery, credential theft, and AI-assisted C2 for advanced post-exploitation activities, including lateral movement and reconnaissance. The library aids in identifying malicious package imports and associated binary artifacts. → rescana.com
Browse all 762 Supply Chain Security resources →

Frequently Asked Questions

What is a software supply chain attack?
A supply chain attack targets the components, tools, or processes used to build software rather than the application itself. This includes compromising open-source packages, injecting malicious code into build pipelines, hijacking maintainer accounts, or distributing trojanized development tools — allowing attackers to affect thousands of downstream users simultaneously.
What is dependency confusion?
Dependency confusion (also called namespace confusion) exploits how package managers resolve dependencies. An attacker publishes a malicious package to a public registry with the same name as a private internal package. If the build system checks the public registry first or prefers higher version numbers, it installs the attacker's package instead of the legitimate internal one.
How do you defend against supply chain attacks?
Key defenses include maintaining a Software Bill of Materials (SBOM), using lock files and dependency pinning, enabling automated dependency scanning (Dependabot, Snyk, Socket), verifying package signatures and provenance, adopting the SLSA framework for build integrity, using private registries with allow-lists, and regularly auditing your dependency tree for known vulnerabilities.

Weekly AppSec Digest

Get new resources delivered every Monday.