Google GTIG Warns of Growing OSS Supply Chain Attacks Targeting Dev Credentials
Google's Threat Intelligence Group (GTIG) published guidance on July 30, 2026, detailing a surge in open-source supply chain attacks targeting developers, maintainers, and CI/CD pipelines. Threat actors including UNC6780 and MIDNIGHT NEPTUNE are stealing credentials via social engineering and abusing GitHub Actions permissions to inject malicious code into legitimate packages on npm, PyPI, and Docker Hub. In one documented case, attackers added malicious dependencies to the widely used axios package, deploying the WAVESHAPER.V2 backdoor and impacting users across 13 countries and 15 industries. Credential-stealing tools like SANDCLOCK enable attackers to self-propagate compromises across repositories and pivot into broader enterprise cloud environments. GTIG recommends phishing-resistant MFA, short-lived OIDC tokens, pinned dependencies with provenance verification, and strict egress controls to reduce exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in