Developer Tooling Compromises Return Across npm, PyPI, and Docker
Developer supply chains are back in the crosshairs. TeamPCP has shifted from credential monetization back to active compromise, and the risk is not just one poisoned package. A compromise in one trusted build or dependency path can now cascade into other developer tools and downstream pipelines.
The week brought three concurrent compromises across npm, PyPI, and Docker Hub. Checkmarx KICS was compromised on April 22, xinference on PyPI was poisoned the same day, and a self-propagating npm worm called CanisterSprawl was identified beginning April 21. The KICS Docker compromise then cascaded into @bitwarden/cli version 2026.4.0 through Bitwarden’s CI/CD automation, and the campaign also remains tied to CVE-2026-33634.
The forward risk is persistence, not novelty. TeamPCP appears to have retained full operational capability after a 26-day pause, and the pattern now favors developer tooling as the fastest way to amplify downstream impact across software supply chains.