Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves
Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves
Read Time:3 Minute, 55 Second

A new analysis from threat intelligence firm ReversingLabs, shared with Cyber Security News, pulls together three separate software supply chain incidents — S1ngularity, Shai-Hulud, and activity linked to a group tracked as TeamPCP — into a single picture of how attackers are turning the ordinary mechanics of software distribution into a credential-harvesting machine. The common thread: once an attacker gets hold of a single maintainer token or slips into an automated release pipeline, they can push malicious code through an update channel that developers and their security tools already implicitly trust.

The report, published September 30, 2026, argues that the danger isn’t confined to any one language ecosystem or vendor. Stolen GitHub tokens, npm publishing credentials, cloud API keys, and SSH keys can each become the opening move in a chain reaction — and in several of the documented cases, credentials stolen from one victim were reused to poison the next release down the line.

S1ngularity: When an AI Assistant Becomes the Attacker’s Search Tool

The S1ngularity campaign, which ReversingLabs dates to August 26, 2025, began when attackers used a crafted pull request against the Nx build tool’s repository to obtain a publishing token and swap in a malicious CI script, ultimately triggering a legitimate-looking publish of infected packages. Once installed on a developer’s machine, those packages ran post-install hooks designed to hunt down tokens, credentials, and SSH keys — then used any GitHub credentials they found on the host to spin up public repositories as a convenient exfiltration channel.

What set the campaign apart was a more unusual twist: the malicious code reportedly issued prompts to local AI coding assistants already installed on the victim’s machine, instructing them to search the file system for likely credential locations such as GitHub and npm tokens, cloud secrets, and SSH keys. In effect, the attackers tried to recruit the developer’s own AI tooling as an unwitting reconnaissance assistant — a technique that goes well beyond a conventional credential stealer. In the aftermath, Nx moved to a trusted-publisher model built on short-lived, per-run credentials specifically to reduce how much damage a single stolen token can do going forward.

Shai-Hulud: A Worm That Spreads Through Trust Itself

Where S1ngularity relied on a one-time pull-request trick, the Shai-Hulud campaign built self-propagation directly into its design. The worm scanned compromised systems for npm publishing credentials, used whatever it found to identify which packages a given victim had permission to publish, and then quietly inserted malicious code into those packages’ next releases. That approach let it spread from project to project without needing to find a fresh software vulnerability at each stop — the compromised credentials themselves did all the work.

TeamPCP and the Trivy Incident: Recycling a Breach

The report also details how a group associated with or possibly overlapping with TeamPCP exploited an earlier breach of the Trivy vulnerability scanner project. A privileged token had been extracted back in February 2026, but an incomplete credential rotation left a residual path open, which attackers used in March to push a malicious update through an automated release system by manipulating version tags relied on by CI/CD workflows. The payload specifically targeted secrets inside running workflow environments, where automation pipelines tend to concentrate valuable credentials in one place.

From there, the group reportedly used npm tokens harvested through the Trivy compromise to distribute a further piece of malware dubbed CanisterWorm, which went on to compromise more than 60 separate npm packages. Downstream, organizations including Checkmarx, LiteLLM, and Telnyx were also caught up in the fallout — a chain that illustrates how a single stolen credential can ripple outward across unrelated companies with no direct relationship to the original breach.

Shoring Up the Software Supply Chain

ReversingLabs frames a successful supply chain compromise as something closer to a full credential breach than a single tainted package, and recommends organizations respond accordingly. Practical steps include:

  • Replace long-lived publishing secrets with short-lived, per-run credentials wherever release tooling supports it.
  • Scope API and publishing tokens as tightly as possible rather than granting broad, standing access.
  • Pin CI/CD pipeline dependencies to specific, reviewed commits instead of trusting mutable tags.
  • Monitor repository and package-publishing activity for anomalies, such as releases that don’t correspond to a known code change.
  • Rotate any token or credential that may have touched an affected build pipeline, and audit for repositories, workflows, or package versions the team didn’t create.

The throughline across all three incidents is that attackers are no longer just looking to plant malware on an endpoint — they’re trying to compromise the publishing process itself, so their code arrives wearing the reputation of a package or vendor the victim already trusts.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves, use the discussion on Forum.

>> forum community

Comments

Leave a Reply