Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Guillaume Valadon
Word Count
596
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

Between April 21 and 23, 2026, three coordinated supply chain attacks targeted npm, PyPI, and Docker Hub, aiming to steal secrets from developer environments and CI/CD pipelines. These attacks sought API keys, cloud credentials, SSH keys, and registry tokens, with each campaign employing distinct methods to achieve this goal. The first attack involved compromising Checkmarx KICS Docker images and VS Code extensions, likely orchestrated by a group known as TeamPCP, which had previously targeted Checkmarx. The second campaign, named CanisterSprawl, used malicious versions of pgserve on npm to propagate a credential-harvesting worm, while the third attack targeted PyPI with xinference releases carrying credential-stealing payloads, also attributed to TeamPCP. Despite technical differences, all attacks shared a common objective: to extract credentials without disrupting software delivery. This highlights the importance of continuous detection and management of secrets across various platforms, as emphasized by GitGuardian's analysis of the cascading damage caused by such supply chain attacks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 6 1,821 338 111 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.