Related Threat Clusters
-
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
Critical SSRF Vulnerability in MLflow Actively Exploited, CISA Issues Warning
A critical SSRF vulnerability (CVE-2026-64849) in MLflow, the world's most downloaded ML platform, allows unauthorized access to metadata services on AWS, Azure, and GCP. The U.S. Cybersecurity and Infrastructure…
2 articles · Updated August 21, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
Shai Hulud npm Worm Compromises Over 26,000 Repositories
The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…
32 articles · Updated November 24, 2025 -
Hackers Exploit Misconfigured Cloud Training Apps in Fortune 500 Firms
Pentera Labs has reported that threat actors are exploiting misconfigured cloud training applications used by Fortune 500 companies and cybersecurity vendors. These vulnerabilities allow attackers to gain unauthorized…
5 articles · Updated January 21, 2026 -
Five Plead Guilty in North Korean IT Worker Fraud Scheme
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
39 articles · Updated November 17, 2025
Recent Intelligence Reports
- Falla crítica en MLflow bajo explotación activa — Ciberseguridadlatam · August 21, 2026
- Megalodon Mass Github Repo Backdooring Ci Workflows — safedep.io · July 19, 2026
- Samsung SDS partners with startups to strengthen AI, cloud security in Korea — Biz.Chosun · June 10, 2026
- Miasma Worm Supply Chain Attack: 73 Microsoft GitHub Repositories Compromised via AI ... — Rescana · June 7, 2026
- durabletask: TeamPCP's Latest PyPi Compromise — Wiz · May 19, 2026
- Expired domain leads to supply chain attack on node — Csoonline · May 15, 2026
- The popular JavaScript library suite 'TanStack,' which is downloaded millions of times every ... — Gigazine · May 12, 2026
- Mini Shai-Hulud Targets SAP npm Packages With a Bun — Aikido.Dev · April 29, 2026