HashiCorp Vault is a technology platform tracked across 8 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 25, 2025; most recent activity July 13, 2026.
HashiCorp Vault is a leading secrets management and data protection platform that centralizes storage, rotation, and access control of credentials such as API keys, tokens, and encryption keys. It provides dynamic (short-lived) credentials, lease-based access, encryption as a service, and flexible authentication methods with policy-driven access control, enabling secure automation across cloud-native environments. This makes it significant in cybersecurity by reducing credential sprawl, enforcing least privilege, and enabling scalable secret management across heterogeneous systems.
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…
A significant supply chain attack has compromised over 400 packages in the Arch User Repository (AUR), with attackers injecting malicious build scripts that deploy credential-stealing malware and rootkits. The campaign,…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Tyler Robert Buchanan, a 24-year-old from Scotland, pleaded guilty in the U.S. to charges of conspiracy to commit wire fraud and aggravated identity theft, linked to a scheme that stole at least $8 million in…
A critical authentication bypass vulnerability has been identified in HashiCorp's Vault Terraform Provider, affecting versions v4.2.0 through the latest release. This flaw allows attackers to authenticate to Vault…
A critical authentication bypass vulnerability has been identified in HashiCorp's Vault Terraform Provider, affecting versions v4.2.0 and later. This flaw allows attackers to authenticate to Vault without valid…