跳到正文
原文
Google Threat Intelligence(GTIG)·· 2026-07-30

Google Threat Intelligence Group 供应链入侵缓解指南:开放源代码软件生态威胁活动激增

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

AI 导读

Google Threat Intelligence Group(GTIG)联合 Mandiant 发布了针对软件供应链入侵的加固与缓解建议,指出 2025 年至 2026 年上半年出现了大规模的开源软件供应链入侵行动,涉及代码仓库、依赖项及开发者工具的攻陷。 其中,UNC6780(又名 TeamPCP)于 2026 年 2 月至 5 月在 PyPI、npm、Docker Hub 发动广泛攻击,滥用 GitHub Actions 的 pull_request_target 触发器获取基础仓库密钥并植入凭证窃取程序 SANDCLOCK,还试图从被感染的 AI 软件横向渗透到企业网络环境。

阅读原文cloud.google.com