Threats · 166 days ago
Multiple recent supply-chain compromises involving Axios npm, Trivy, KICS, LiteLLM, and Telnyx have led to the theft of build and runtime secrets. Attackers, including TeamPCP and North Korea-linked groups, rapidly validate and reuse these secrets to access cloud environments, exfiltrate data, and conduct extortion. This chain of events turns isolated supply-chain breaches into ongoing multi-tenant cloud intrusions.
Affected organizations must assume that secrets tied to these compromised packages or services are exposed, even if their own code is intact. Standard patching and dependency checks do not detect this lateral movement. Teams should prioritize hunting for unauthorized cloud logins, rotating credentials, and auditing service principals and downstream customer access to contain the threat.
1 source covering this story
Software supply chain hacks trigger wave of intrusions, data theft - Help Net Security
The secrets stolen in recent software supply chain attacks are being used for further intrusions and data theft, leading to cyber extortion.
Part of the PlainSec briefing for 2026-04-02