[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJ6Ry_DgWgzuvV-aeAqwzKRaJ7Q_TUVFNlh8H1_1R4ug":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"d32fe88f-4ab9-43a5-a958-5bc99daa8540","malicious-code-injected-into-open-source-libraries-compromises-1000-organizations","f24bae11-925e-487b-9f78-71b47724280d","Malicious Code Injected into Open-Source Libraries Compromises 1,000+ Organizations","TeamPCP exploited the inherent trust organizations place in open-source software by injecting malicious code directly into widely-used libraries such as TanStack and UiPath, turning legitimate dependencies into attack vectors. This supply chain attack demonstrates how a single compromised package can cascade across hundreds of thousands of downstream users and systems simultaneously. The scale of credential exposure and the millions spent in cleanup underscore that organizations often lack sufficient controls to detect or respond to tampered third-party code. Investigators were ultimately able to identify suspects through poor operational security — leaked passwords and publicly linked online profiles — highlighting that attackers are not infallible, but the damage is done long before attribution occurs.","**Immediate actions:**\n- Audit all current open-source dependencies against known-compromised package versions and remove or pin them to verified safe releases.\n- Scan your software bill of materials (SBOM) for any packages associated with the affected libraries (TanStack, UiPath integrations, Trivy) and treat them as untrusted until verified.\n\n**Long-term improvements:**\n- Mandate the generation and maintenance of a comprehensive SBOM for every application so dependency risks can be rapidly assessed during future incidents.\n- Implement a private, vetted package registry or artifact repository (e.g., Artifactory, Nexus) to proxy and vet all open-source packages before they reach development pipelines.\n- Establish a formal third-party and open-source risk management policy that includes periodic integrity checks and code-signing verification for all external dependencies.\n\n**Detection measures:**\n- Deploy runtime application self-protection (RASP) or behavioural monitoring to detect anomalous activity originating from third-party library code.\n- Integrate software composition analysis (SCA) tools into CI\u002FCD pipelines to automatically flag newly published vulnerabilities or integrity mismatches in dependencies before deployment.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST SSDF (SP 800-218): Secure Software Development Framework","NIST CSF: ID.SC-4 (Suppliers and third-party partners are routinely assessed)","SLSA Framework: Supply-chain Levels for Software Artifacts","GDPR Article 32: Security of Processing (credential exposure liability)","ISO\u002FIEC 27036: Information Security for Supplier Relationships","OWASP A06:2021 – Vulnerable and Outdated Components","published","2026-08-27T16:20:20.430291+00:00","2026-08-27T16:20:20.33+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fcyberscoop.com\u002Fteampcp-cybercrime-arrests-supply-chain-attacks\u002F","two-alleged-teampcp-members-arrested-and-charged-after-months-of-software-supply-abab26","Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]