Attackers Are Still Coming for Security Companies. Here's Where We Stand.
Blog post from Semgrep
The TeamPCP campaign highlights the persistent challenge of supply chain security in the software industry, affecting reputable organizations like Trivy, Checkmarx, and Bitwarden despite their strong security measures. Beginning in February, attackers exploited a common CI vulnerability, a misconfiguration in GitHub Actions workflows, to gain unauthorized access and expand their reach by compromising various platforms, including npm packages, Docker Hub, and VS Code extensions. The attackers used stolen credentials to infiltrate CI/CD pipelines, with significant incidents involving malicious code injection that harvested sensitive data. The campaign underscores the importance of structural controls, such as pinning GitHub Actions to immutable SHAs and implementing package cooldowns, to mitigate risks. Security teams are advised to scrutinize their CI environments and credential access points to better prepare against potential breaches, as the campaign continues to evolve with no clear end in sight.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 1,821 | 338 | 111 | +22% |
| Kubernetes | 1 | 2,306 | 381 | 103 | +25% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.