Security · 1h ago
Google warns of OSS supply chain attacks stealing credentials
Google Threat Intelligence Group details a growing attack model where threat actors compromise developer accounts and CI/CD pipelines to inject malicious code into legitimate packages on npm, PyPI, and Docker Hub. The attacks, including those targeting axios, steal cloud credentials and self-propagate to other packages, leading to ransomware or extortion. Mitigation includes phishing-resistant MFA, short-lived OIDC tokens, and restricting install scripts.
Meridian48 take
The report underscores that open-source trust is fragile, but the guidance is standard hygiene—adoption remains the real challenge.
Read the full reporting
GTIG: 2026 OSS Supply Chain Compromise, Credential Theft, and Self-Propagation →
DEV Community
supply-chain-securitycredential-theft