CVE-2026-33634
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr · data superata
Minacce e avversari · Supply chain
Developer supply chains are back in the crosshairs. TeamPCP has shifted from credential monetization back to active compromise, and the risk is not just one poisoned package. A compromise in one trusted build or dependency path can now cascade into other developer tools and downstream pipelines.
The week brought three concurrent compromises across npm, PyPI, and Docker Hub. Checkmarx KICS was compromised on April 22, xinference on PyPI was poisoned the same day, and a self-propagating npm worm called CanisterSprawl was identified beginning April 21. The KICS Docker compromise then cascaded into @bitwarden/cli version 2026.4.0 through Bitwarden’s CI/CD automation, and the campaign also remains tied to CVE-2026-33634.
The forward risk is persistence, not novelty. TeamPCP appears to have retained full operational capability after a 26-day pause, and the pattern now favors developer tooling as the fastest way to amplify downstream impact across software supply chains.
1 fonte · 27 apr
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr · data superata
SANS ISC
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, Author: Kenneth Hartman
originalePart of the PlainSec briefing for 2026-04-27
Every edition of this story: Developer Tooling Compromises Return Across npm, PyPI, and Docker