TeamPCP Supply Chain Campaign Poisons Checkmarx KICS, Bitwarden CLI, and PyPI Packages to Steal Cloud Credentials at Scale
A financially motivated threat group tracked as TeamPCP has executed at least seven waves of sophisticated supply chain attacks since March 2026, poisoning trusted CI/CD tools including Checkmarx...
84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials
Attackers compromised 84 npm artifacts across 42 TanStack packages — including react-router with 12M+ weekly downloads — injecting a credential-stealing payload via chained GitHub Actions abuse. Organizations that...
Foxconn Confirms Cyberattack: Nitrogen Ransomware Gang Claims 8TB Stolen From North American Plants
Foxconn has confirmed a ransomware attack on its North American factories after the Nitrogen gang claimed to have stolen 8TB of data including technical drawings and network topology...
DigiCert Breached via Weaponized Screensaver: Threat Actor Steals EV Code Signing Certificates to Spread Zhong Stealer
A sophisticated threat actor breached DigiCert's internal support environment in early April 2026 by tricking analysts into executing a disguised .scr malware file, ultimately obtaining EV Code Signing...
Trellix Source Code Breach: Hackers Gain Unauthorized Access to Internal Repository of Major XDR Vendor
Cybersecurity vendor Trellix has confirmed unauthorized access to part of its internal source code repository. The company says no evidence of product tampering or active exploitation has been...
Bitwarden CLI npm Package Compromised in Sophisticated GitHub Actions Supply Chain Attack
Security researchers at Socket have confirmed that the official Bitwarden CLI npm package (version 2026.4.0) was tampered with via a compromised GitHub Actions workflow, injecting credential-stealing malware as...
GlassWorm Escalates: 73 New “Sleeper” Extensions Discovered on Open VSX Marketplace
Aikido Security has identified 73 new GlassWorm "sleeper" extensions on the Open VSX marketplace, marking a dangerous escalation in a supply chain campaign targeting developers through hidden malicious...
Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend
JFrog Security researchers have uncovered a malicious npm package, js-logger-pack, that uses Hugging Face as both a malware delivery network and an exfiltration backend for stolen data. The...