No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours
Blog post from GitGuardian
Between April 21 and 23, 2026, three coordinated supply chain attacks targeted npm, PyPI, and Docker Hub, aiming to steal secrets from developer environments and CI/CD pipelines. These attacks sought API keys, cloud credentials, SSH keys, and registry tokens, with each campaign employing distinct methods to achieve this goal. The first attack involved compromising Checkmarx KICS Docker images and VS Code extensions, likely orchestrated by a group known as TeamPCP, which had previously targeted Checkmarx. The second campaign, named CanisterSprawl, used malicious versions of pgserve on npm to propagate a credential-harvesting worm, while the third attack targeted PyPI with xinference releases carrying credential-stealing payloads, also attributed to TeamPCP. Despite technical differences, all attacks shared a common objective: to extract credentials without disrupting software delivery. This highlights the importance of continuous detection and management of secrets across various platforms, as emphasized by GitGuardian's analysis of the cascading damage caused by such supply chain attacks.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 6 | 1,821 | 338 | 111 | +22% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.