Ongoing Supply Chain Attack Expands to PyPi
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
All topics
Researchers have linked the compromise to the "Mini Shai-Hulud" campaign, which has been ongoing for several weeks and is associated with TeamPCP.
Yet another supply chain attack has hit the open source ecosystem, this time impacting the Checkmarx KICS Docker Hub repository.
Axios is a dependency in nearly 80% of all cloud and code environments and sees approximately 100 million downloads per week.
TeamPCP’s latest victim is the Telnyx Python SDK on PyPl, coming after a wave of supply chain hits on Aqua Trivy, Checkmarx KICS/OpenVSX, and LiteLLM.
GitHub said the changes will help "fortify the security of the software supply chain" after a recent surge of attacks targeting the npm ecosystem.