Three supply chain attacks hit npm, PyPI, and Docker Hub between April 21–23, 2026. All three targeted secrets: API keys, cloud credentials, SSH keys, and tokens from developer environments and CI/CD pipelines.
The post No Off Season: Three Supply Chain Campaigns Hit npm, PyPI, and Docker Hub in 48 Hours appeared first on Security Boulevard.
Guillaume Valadon
Source: Security Boulevard
Source Link: https://securityboulevard.com/2026/04/no-off-season-three-supply-chain-campaigns-hit-npm-pypi-and-docker-hub-in-48-hours/