Critical Flaws in JetBrains TeamCity Let Attackers Steal Credentials
Key Takeaways Attackers are increasingly exploiting trusted software update mechanisms to compromise development environments. Recent incidents, including S1ngularity, Shai-Hulud, and TeamPCP,...
Key Takeaways
- Attackers are increasingly exploiting trusted software update mechanisms to compromise development environments.
- Recent incidents, including S1ngularity, Shai-Hulud, and TeamPCP, demonstrate how compromised build actions or publishing tokens can lead to widespread credential theft.
- Stolen credentials (GitHub, npm, cloud, SSH) provide access to critical resources like source code and deployment systems, enabling further attacks.
- Malicious code has been observed leveraging local AI tools to discover credential locations, representing an evolving threat vector.
- Organizations must adopt robust security practices, including using short-lived tokens, limiting permissions, and monitoring CI/CD pipelines to mitigate these supply chain risks.
The cybersecurity landscape is witnessing a concerning trend: malicious actors are weaponizing seemingly innocuous software updates to infiltrate development ecosystems and pilfer sensitive developer and cloud credentials. These supply chain attacks leverage a single compromised element—be it an altered package, a malicious build action, or a stolen publishing token—to inject malware directly into routine software development workflows.
Table Of Content
This threat is not confined to a specific product or programming language. Once an attacker gains control of a maintainer token or secures access to an automated release pipeline, they can distribute malicious code disguised as a legitimate update. Such updates often bypass traditional security measures and user scrutiny due to their trusted origin.
According to ReversingLabs in a report shared with Cyber Security News (CSN), incidents like S1ngularity, Shai-Hulud, and TeamPCP vividly illustrate the rapid propagation potential of such compromises. A breach at one supplier can quickly ripple through numerous downstream organizations, exposing a vast network to risk.
The report details a dangerous cycle of stolen credentials, poisoned software releases, and subsequent attacks across various open-source platforms. The repercussions extend far beyond individual developer workstations. Compromised GitHub, npm, cloud, and SSH credentials can grant unauthorized access to proprietary source code, critical cloud infrastructure, deployment systems, and other software packages. In several documented instances, malware has utilized credentials harvested from one victim to publish the next wave of poisoned updates.
Hackers Poison Trusted Software Updates
The S1ngularity incident serves as a stark example of why trusted software distribution channels are prime targets for attackers. In this case, threat actors compromised Nx packages. They achieved this by exploiting a crafted pull request to obtain a token, subsequently replacing a Continuous Integration (CI) script, and then triggering a malicious publishing workflow.
These infected packages executed post-installation hooks on developer machines. This method of credential theft via Nx packages was previously covered by CSN during the 2025 campaign. The hooks were designed to scour systems for valuable data, including various tokens, credentials, and SSH keys. Furthermore, the malware leveraged any GitHub credentials discovered on the host to create public repositories, establishing a direct exfiltration route for the stolen data. Uniquely, this campaign also involved the malicious code prompting local AI tools to identify potential credential storage locations on the file system.
The ReversingLabs report, published on September 30, 2026, places the Nx compromise on August 26, 2025. It differentiates the original S1ngularity campaigns from TeamPCP, as no definitive link has been established between TeamPCP and earlier incidents. The report highlights that the AI tool prompts specifically sought GitHub and npm tokens, cloud credentials, and SSH keys, illustrating an advanced tactic to transform a developer’s own AI assistant into an internal reconnaissance tool for credential discovery. This illustrates a broader impact of AI tool credential targeting, including the specific data the malware aimed to exfiltrate from affected systems.
The S1ngularity case also underscored the inherent risks associated with long-lived publishing tokens. The stolen npm token allowed the release of compromised packages, which then benefited from the established reputation of the legitimate software. Recognizing this vulnerability, Nx subsequently implemented a trusted-publisher model, utilizing short-lived, per-run credentials to diminish the utility of any tokens stolen from repositories.
Credential Worms
Building on this attack model, the Shai-Hulud worm introduced a self-propagating mechanism. This credential worm actively scanned compromised systems for npm publishing credentials. Upon discovery, it identified packages that the victim had permission to publish and injected malicious code into subsequent releases. This allowed Shai-Hulud to spread autonomously without requiring a fresh software vulnerability at each new target, as detailed in the Shai-Hulud worm attack investigation.
Subsequent activity associated with TeamPCP demonstrated how threat actors can effectively reuse previously obtained access. In the Trivy incident, a privileged token was initially extracted in February 2026. Due to incomplete credential rotation, attackers exploited this lingering access to publish a malicious update on March 19 through an automated system. The attackers manipulated version tags within CI/CD workflows, a technique highlighted in CSN’s <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/5fcce754-ecf2-4ed0-9fa4-64d7
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.