CVE-2026-33634
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr · data superata
Minacce · 155 giorni fa
Developer supply chains are back in the crosshairs. TeamPCP has shifted from credential monetization back to active compromise, and the risk is not just one poisoned package. A compromise in one trusted build or dependency path can now cascade into other developer tools and downstream pipelines.
The week brought three concurrent compromises across npm, PyPI, and Docker Hub. Checkmarx KICS was compromised on April 22, xinference on PyPI was poisoned the same day, and a self-propagating npm worm called CanisterSprawl was identified beginning April 21. The KICS Docker compromise then cascaded into @bitwarden/cli version 2026.4.0 through Bitwarden’s CI/CD automation, and the campaign also remains tied to CVE-2026-33634.
The forward risk is persistence, not novelty. TeamPCP appears to have retained full operational capability after a 26-day pause, and the pattern now favors developer tooling as the fastest way to amplify downstream impact across software supply chains.
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr · data superata
1 fonte che coprono questa storia
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, Author: Kenneth Hartman
Part of the PlainSec briefing for 2026-04-28