Ongoing Supply Chain Attack Expands to PyPi
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
All topics
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
Yet another supply chain attack has hit the open source ecosystem, this time impacting the Checkmarx KICS Docker Hub repository.
Dennis and Lindsey dig into what we know do far about the supply chain attack on the axios NPM package, including how the attacker gained access to the maintainer’s account, the window of exposure for the malicious packages, the behavior of the RAT that’s installed on victims’ machines, and what the downstream effects may be.
Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.
TeamPCP’s latest victim is the Telnyx Python SDK on PyPl, coming after a wave of supply chain hits on Aqua Trivy, Checkmarx KICS/OpenVSX, and LiteLLM.
The vulnerability was disclosed publicly on Dec. 3 and researchers and threat intelligence teams immediately began seeing opportunistic and targeted exploitation attempts.